CVE-2024-12370

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 284

Summary

CVE-2024-12370 is a vulnerability affecting the WP Hotel Booking plugin for WordPress. This issue arises from a missing capability check in all versions up to 2.1.5, allowing unauthenticated attackers to add rooms with custom prices. This unauthorized modification of data poses a significant security risk, potentially leading to financial loss or other undesirable consequences for affected websites. To mitigate this vulnerability, it is recommended that users upgrade to the latest version of the plugin as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share