Description
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9.
Published: 2025-05-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CSRF flaw in the ThimPress WP Hotel Booking plugin, allowing an attacker to craft a request that triggers privileged actions on a WordPress site without the user’s knowledge. The vulnerability can be used to create, modify, or delete bookings when another user visits a page that submits a malicious POST to the booking handler. It is identified as CWE‑352. The impact is that an authenticated user may perform unintended booking operations, potentially leading to data integrity and availability problems for the booking system.

Affected Systems

The flaw affects all installations of WP Hotel Booking version 2.1.9 and older, which includes the 2.1.9 branch and any earlier releases. The vendor is ThimPress and the plugin is known as WP Hotel Booking. No further version granularity is listed, so any site running a vulnerable version is at risk.

Risk and Exploitability

Current CVSS score is 4.3, indicating moderate severity. EPSS score is below 1%, implying low likelihood of widespread exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker could exploit the flaw by hosting a malicious page that forces a victim administrator to unknowingly submit a booking request. The attack vector is online and does not require a compromised authentication state; it relies on the victim’s authenticated session cookie. Because the flaw does not allow arbitrary code execution, it mainly presents a risk of unauthorized data modification rather than full system compromise.

Generated by OpenCVE AI on April 30, 2026 at 20:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Hotel Booking plugin to the latest available version (any release newer than 2.1.9).
  • After upgrading, verify that the plugin’s booking endpoints enforce CSRF tokens and reject unauthenticated requests.
  • If an update cannot be performed immediately, restrict the booking editor capability to a narrow set of trusted administrators and enable additional authentication checks, such as two‑factor authentication, for high‑privilege booking actions.

Generated by OpenCVE AI on April 30, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13863 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9. Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9.
Title WordPress WP Hotel Booking <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability WordPress WP Hotel Booking plugin <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.0002}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.
Title WordPress WP Hotel Booking <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Thimpress Wp Hotel Booking
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:40.907Z

Reserved: 2025-05-07T09:38:40.259Z

Link: CVE-2025-47448

cve-icon Vulnrichment

Updated: 2025-05-07T17:21:35.556Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:15:58.903

Modified: 2026-04-23T15:30:14.107

Link: CVE-2025-47448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:45:36Z

Weaknesses