CVE-2024-9450

MEDIUM

Syntacticsinc Easync < 1.3.15 - CSRF

Title source: rule

Description

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-352
Status published

Affected Products (1)

syntacticsinc/easync < 1.3.15

Timeline

Published May 15, 2025
Tracked Since Feb 18, 2026