T
he Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ | Exploit Third Party Advisory |
Configurations
History
23 Jan 2026, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Syntacticsinc
Syntacticsinc easync |
|
| CPE | cpe:2.3:a:syntacticsinc:easync:*:*:*:*:*:wordpress:*:* |
04 Jun 2025, 20:06
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-352 | |
| First Time |
Syntactics
Syntactics free Booking Plugin For Hotels\, Restaurant And Car Rental |
|
| CPE | cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:* | |
| References | () https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ - Exploit, Third Party Advisory |
16 May 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
16 May 2025, 14:42
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
15 May 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-15 20:16
Updated : 2026-01-23 19:32
NVD link : CVE-2024-9450
Mitre link : CVE-2024-9450
CVE.ORG link : CVE-2024-9450
JSON object : View
Products Affected
CWE
CWE-352
Cross-Site Request Forgery (CSRF)