Cross-Site Request Forgery Vulnerability in MagePeople Bus Ticket Booking System
CVE-2024-49294
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 January 2025
What is CVE-2024-49294?
A security issue has been identified in the MagePeople Bus Ticket Booking with Seat Reservation plugin, allowing unauthorized actions via Cross-Site Request Forgery (CSRF). This vulnerability can be exploited to perform actions on behalf of users without their consent, posing a significant risk to user accounts and sensitive information. All versions from n/a up to 5.4.3 are affected, and users are urged to update to the latest version to mitigate potential attacks.
Affected Version(s)
Bus Ticket Booking with Seat Reservation <= 5.4.3