The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.
History

Wed, 12 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Thimpress
Thimpress wp Hotel Booking
Weaknesses CWE-862
CPEs cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*
Vendors & Products Thimpress
Thimpress wp Hotel Booking

Fri, 17 Jan 2025 08:30:00 +0000

Type Values Removed Values Added
Description The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.
Title WP Hotel Booking <= 2.1.5 - Missing Authorization
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-12T16:54:07.689Z

Reserved: 2024-12-09T16:34:30.012Z

Link: CVE-2024-12370

cve-icon Vulnrichment

Updated: 2025-02-12T16:53:55.971Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-17T09:15:07.810

Modified: 2025-02-11T21:42:23.220

Link: CVE-2024-12370

cve-icon Redhat

No data.