Free Booking Plugin for WordPress CSRF Vulnerability (CVE-2024-9450) — Medium Severity

Understanding the Free Booking Plugin Vulnerability

A security flaw has been found in the Free Booking Plugin for Hotels, Restaurants and Car Rentals, also known as eaSYNC Booking, a popular WordPress plugin. This vulnerability, identified as CVE-2024-9450, could allow attackers to make unwanted changes to a website’s settings without the user’s knowledge. It’s a type of attack called Cross-Site Request Forgery (CSRF).

In simple terms, a CSRF attack tricks a logged-in user into performing actions they didn’t intend. For this plugin, it means an attacker could potentially trick an administrator or any logged-in subscriber into changing plugin settings, like PayPal configuration, simply by visiting a malicious webpage.

CVE Details

  • Product: Free Booking Plugin for Hotels, Restaurants and Car Rentals (eaSYNC Booking) for WordPress
  • CVE ID: CVE-2024-9450
  • Published Date: May 15, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts versions of the Free Booking Plugin for Hotels, Restaurants and Car Rentals (eaSYNC Booking) for WordPress prior to 1.3.15. If you are using any version older than 1.3.15, your website may be at risk.

Current Status

This vulnerability has been officially analyzed. This means security researchers and vendors have investigated the flaw and confirmed its existence and potential impact. Information about the vulnerability is now publicly available to help users protect their systems.

Severity Level

The Common Vulnerability Scoring System (CVSS) has rated this vulnerability with a score of 4.1, classifying it as Medium severity. While not critical, a Medium severity rating indicates that the vulnerability could still lead to noticeable impact if exploited. In this case, attackers could manipulate sensitive plugin settings like PayPal configurations, which could disrupt services or lead to financial implications.

Possible Solutions

The good news is that a fix is available. To protect your WordPress website from this CSRF vulnerability, it is crucial to update your Free Booking Plugin for Hotels, Restaurants and Car Rentals (eaSYNC Booking) to version 1.3.15 or later. Developers of the plugin have addressed the missing CSRF check in this updated version.

Always ensure your WordPress core, themes, and plugins are kept up-to-date to maintain the best possible security posture for your website.

References

https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.