The Free Booking Plugin for Hotels, Restaurants and Car Rentals  WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    04 Jun 2025, 20:06
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-15 20:16
Updated : 2025-06-04 20:06
NVD link : CVE-2024-9450
Mitre link : CVE-2024-9450
CVE.ORG link : CVE-2024-9450
JSON object : View
Products Affected
                syntactics
- free_booking_plugin_for_hotels\,_restaurant_and_car_rental
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
