Showing 5 vulnerabilities on this page for wp_hotel_booking

Signals CISA KEV Ransomware Nuclei
thimpress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

CWE-22CWE-35Nov 4, 2024
CVSS7.5v3.1EPSS0.525%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CWE-434Oct 2, 2024
CVSS8.8v3.1EPSS17.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the da

CWE-89Jun 20, 20241 related artifact
CVSS10.0v3.1EPSS4.19%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

CWE-862Mar 29, 2024
CVSS6.5v3.1EPSS0.519%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

thimpress wp_hotel_booking Deserialization of Untrusted Data

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

CWE-502Mar 3, 20211 related artifact
CVSS9.8v3.1EPSS16%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX