Skip to main content
Vulnerability Database/CVE-2024-12370

CVE-2024-12370: WP Hotel Booking Auth Bypass Vulnerability

CVE-2024-12370 is an authentication bypass flaw in WP Hotel Booking plugin that allows unauthenticated attackers to add rooms with custom prices. This post covers the technical details, affected versions, and mitigation.

Published:

CVE-2024-12370 Overview

CVE-2024-12370 affects the WP Hotel Booking plugin for WordPress, developed by ThimPress. The vulnerability stems from a missing capability check in the room creation functionality across all versions up to and including 2.1.5. Unauthenticated attackers can add rooms with arbitrary custom prices to affected sites. The flaw is classified under [CWE-862] Missing Authorization and [CWE-284] Improper Access Control. ThimPress addressed the issue in version 2.1.6 through a changeset that enforces capability validation.

Critical Impact

Unauthenticated remote attackers can create hotel room entries with attacker-controlled pricing, enabling data integrity abuse and potential business logic manipulation on booking workflows.

Affected Products

  • ThimPress WP Hotel Booking plugin for WordPress, versions up to and including 2.1.5
  • WordPress sites with WP Hotel Booking installed and activated
  • WP Hotel Booking plugin tag 2.1.5 and prior release branches

Discovery Timeline

  • 2025-01-17 - CVE-2024-12370 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-12370

Vulnerability Analysis

The WP Hotel Booking plugin exposes room creation functionality without verifying the caller's privileges. The handler responsible for adding rooms does not call a WordPress capability check such as current_user_can() before processing input. As a result, any unauthenticated HTTP request reaching that endpoint can create a persistent room record.

Attackers can set custom prices on the newly created rooms. This introduces fraudulent inventory into the booking system and corrupts data integrity. Downstream workflows that trust plugin data, including public listings, reservation flows, and payment calculations, can be influenced by the injected content.

The issue is a classic Broken Access Control defect. The business logic function was reachable through the plugin's AJAX or admin-post surface without authentication boundaries. The EPSS probability currently sits at 0.318%, indicating low observed exploitation activity.

Root Cause

The plugin registers a room-add action handler but omits authorization validation. Both [CWE-862] Missing Authorization and [CWE-284] Improper Access Control apply. The vendor patch introduced in version 2.1.6 adds the missing capability check so that only authorized users with appropriate roles can invoke the room creation logic.

Attack Vector

Exploitation requires only network access to the target WordPress site. No authentication, user interaction, or elevated privileges are needed. An attacker sends a crafted POST request to the plugin's registered action endpoint, supplying room parameters and a chosen price value. The server processes the request and persists the room because no capability check gates execution.

No public proof-of-concept exploit code is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. See the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2024-12370

Indicators of Compromise

  • Unexpected room entries in the WP Hotel Booking database tables, especially rooms with unusual pricing or non-standard titles
  • POST requests to admin-ajax.php or plugin action endpoints referencing WP Hotel Booking room creation actions from unauthenticated sessions
  • New wp_posts records of the plugin's custom post type created without a corresponding authenticated administrator session in access logs

Detection Strategies

  • Audit the WordPress database for room records created after plugin installation and reconcile against legitimate administrator activity
  • Correlate web server access logs with WordPress authentication logs to identify room creation requests lacking valid session cookies
  • Monitor plugin-specific AJAX actions for anonymous invocation patterns and flag high-frequency or anomalous source IP addresses

Monitoring Recommendations

  • Enable verbose logging on the WordPress site and forward events to a central SIEM for correlation and retention
  • Alert on creation of new custom post type entries belonging to WP Hotel Booking outside maintenance windows
  • Track outbound notifications or booking confirmations tied to rooms that were not provisioned through normal workflows

How to Mitigate CVE-2024-12370

Immediate Actions Required

  • Upgrade the WP Hotel Booking plugin to version 2.1.6 or later on every affected WordPress installation
  • Review the WP Hotel Booking database tables and remove any rooms created without authorization
  • Rotate administrator credentials and audit user roles if unauthorized changes are observed

Patch Information

ThimPress released the fix in WP Hotel Booking version 2.1.6. The code change is documented in the WordPress Plugin Changeset between tags 2.1.5 and 2.1.6. Site administrators should apply the update through the WordPress plugin manager or via WP-CLI.

Workarounds

  • Deactivate the WP Hotel Booking plugin until the upgrade to 2.1.6 can be deployed
  • Restrict access to wp-admin/admin-ajax.php and plugin action endpoints with a web application firewall rule that requires authenticated sessions for room creation actions
  • Place the WordPress site behind IP allowlisting for administrative paths where business requirements permit
bash
# Upgrade WP Hotel Booking using WP-CLI
wp plugin update wp-hotel-booking --version=2.1.6
wp plugin get wp-hotel-booking --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.