CVE-2024-12370
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 17, 2025
CWE ID 284
Summary
CVE-2024-12370 is a vulnerability affecting the WP Hotel Booking plugin for WordPress. This issue arises from a missing capability check in all versions up to 2.1.5, allowing unauthenticated attackers to add rooms with custom prices. This unauthorized modification of data poses a significant security risk, potentially leading to financial loss or other undesirable consequences for affected websites. To mitigate this vulnerability, it is recommended that users upgrade to the latest version of the plugin as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.