Medium severity5.3NVD Advisory· Published Jan 17, 2025· Updated Jun 17, 2026
CVE-2024-12370
CVE-2024-12370
Description
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*range: <2.1.6
- (no CPE)range: 0
<=2.1.5+ 1 more
- (no CPE)range: <=2.1.5
- (no CPE)
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/5df32365-5381-48e0-9313-7e83c4c6c440nvdThird Party Advisory
News mentions
0No linked articles in our index yet.