Cross-Site Request Forgery Vulnerability in Oganro Travel Portal Search Widget by Oganro
CVE-2025-49966
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2025
What is CVE-2025-49966?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Oganro Travel Portal Search Widget for the HotelBeds APITUDE API. This vulnerability can allow attackers to exploit the application by tricking authenticated users into submitting unwanted actions without their consent. The issue is present in versions from n/a up to and including 1.0, posing a threat to the integrity of user interactions with the platform.
Affected Version(s)
Oganro Travel Portal Search Widget for HotelBeds APITUDE API <= 1.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Chu The Anh (Blue Rock) (Patchstack Alliance)