The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ | Exploit Third Party Advisory |
Configurations
History
23 Jan 2026, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Syntacticsinc
Syntacticsinc easync |
|
| CPE | cpe:2.3:a:syntacticsinc:easync:*:*:*:*:*:wordpress:*:* |
04 Jun 2025, 20:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:* | |
| CWE | CWE-352 | |
| References | () https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ - Exploit, Third Party Advisory | |
| First Time |
Syntactics
Syntactics free Booking Plugin For Hotels\, Restaurant And Car Rental |
16 May 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
16 May 2025, 14:42
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
15 May 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-15 20:16
Updated : 2026-01-23 19:32
NVD link : CVE-2024-9450
Mitre link : CVE-2024-9450
CVE.ORG link : CVE-2024-9450
JSON object : View
Products Affected
syntacticsinc
- easync
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
