CVE-2024-12370: Thimpress Wp Hotel Booking
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.
Affected products
- Thimpress Wp Hotel Booking: before 2.1.6 (fixed in 2.1.6)
Published 2025-01-17. Last modified 2026-06-17.