CVE-2024-12370

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*

History

11 Feb 2025, 21:42

Type Values Removed Values Added
First Time Thimpress
Thimpress wp Hotel Booking
CWE CWE-862
CPE cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento WP Hotel Booking para WordPress es vulnerable a la modificación no autorizada de datos debido a una verificación de capacidad faltante al agregar habitaciones en todas las versiones hasta la 2.1.5 incluida. Esto hace posible que atacantes no autenticados agreguen habitaciones con precios personalizados.
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3210798%40wp-hotel-booking%2Ftags%2F2.1.5&new=3214765%40wp-hotel-booking%2Ftags%2F2.1.6 - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3210798%40wp-hotel-booking%2Ftags%2F2.1.5&new=3214765%40wp-hotel-booking%2Ftags%2F2.1.6 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/5df32365-5381-48e0-9313-7e83c4c6c440?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/5df32365-5381-48e0-9313-7e83c4c6c440?source=cve - Third Party Advisory

17 Jan 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-17 09:15

Updated : 2025-02-11 21:42


NVD link : CVE-2024-12370

Mitre link : CVE-2024-12370

CVE.ORG link : CVE-2024-12370


JSON object : View

Products Affected

thimpress

  • wp_hotel_booking
CWE
CWE-284

Improper Access Control

CWE-862

Missing Authorization