Cross-Site Request Forgery Vulnerability in Oganro Travel Portal Search Widget by Oganro
CVE-2025-49966
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2025
What is CVE-2025-49966?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Oganro Travel Portal Search Widget for the HotelBeds APITUDE API. This vulnerability can allow attackers to exploit the application by tricking authenticated users into submitting unwanted actions without their consent. The issue is present in versions from n/a up to and including 1.0, posing a threat to the integrity of user interactions with the platform.
Affected Version(s)
Oganro Travel Portal Search Widget for HotelBeds APITUDE API <= 1.0