📦 Wp Hotel Booking

by Thimpress

🔍 What is Wp Hotel Booking?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3605

CRITICAL CVSS 10.0 Jun 20, 2024

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the WP Hotel Booking plugin. By manipulating the 'room_type' parameter in the REST API end...

CVE-2023-5652

CRITICAL CVSS 9.8 Nov 20, 2023

CVE-2023-5652 is a critical SQL injection vulnerability in the WP Hotel Booking WordPress plugin. Unauthenticated attackers can exploit missing authorization and input sanitization to execute arbitrar...

CVE-2020-29047

CRITICAL CVSS 9.8 Mar 3, 2021

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites using the wp-hotel-booking plugin through version 1.10.2. Attackers can exploit insecure deserialization in the ...

CVE-2024-51582

HIGH CVSS 7.5 Nov 4, 2024

This path traversal vulnerability in the ThimPress WP Hotel Booking WordPress plugin allows attackers to include local PHP files using '.../...//' sequences. It affects all WordPress sites running WP ...

CVE-2024-12370

MEDIUM CVSS 5.3 Jan 17, 2025

The WP Hotel Booking plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to add rooms with custom prices. This affects all WordPress sites using the pl...