CVE-2024-9450

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:*

History

04 Jun 2025, 20:06

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:16

Updated : 2025-06-04 20:06


NVD link : CVE-2024-9450

Mitre link : CVE-2024-9450

CVE.ORG link : CVE-2024-9450


JSON object : View

Products Affected

syntactics

  • free_booking_plugin_for_hotels\,_restaurant_and_car_rental
CWE
CWE-352

Cross-Site Request Forgery (CSRF)