Cross-Site Request Forgery Vulnerability in ThimPress WP Hotel Booking Plugin
CVE-2025-63012

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2025-63012?

The WP Hotel Booking plugin developed by ThimPress has been identified to have a Cross-Site Request Forgery (CSRF) vulnerability. This vulnerability allows an attacker to perform unwanted actions on behalf of an authenticated user without their consent. Affected versions of this plugin are up to 2.2.7, making users susceptible to unauthorized changes and actions, which could compromise the integrity and security of their hotel booking systems.

Affected Version(s)

WP Hotel Booking <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.