CVE-2024-30508: WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability
Published Mar 29, 2024
·Updated
Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.
Affected Software
2 affected components
thimpress Wp Hotel Booking Wordpress<2.0.9.3
thimpress WP Hotel Booking<=2.0.9.2
Remediation
Information
Update to 2.0.9.3 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 57087
Event
via NVD·02:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-30508?
The severity of CVE-2024-30508 is considered high due to its potential for unauthorized access.
2
How do I fix CVE-2024-30508?
To fix CVE-2024-30508, update the WP Hotel Booking plugin to version 2.0.9.3 or later.
3
What version of WP Hotel Booking is affected by CVE-2024-30508?
CVE-2024-30508 affects WP Hotel Booking versions from n/a through 2.0.9.2.
4
Is CVE-2024-30508 related to unauthorized access?
Yes, CVE-2024-30508 is a missing authorization vulnerability that can lead to unauthorized access.
5
Who is affected by CVE-2024-30508?
Any user running WP Hotel Booking versions up to 2.0.9.2 is affected by CVE-2024-30508.