CVE-2020-29047
thimpress wp_hotel_booking Deserialization of Untrusted Data
Record summary
CVE-2020-29047 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 17, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wp_hotel_bookingBrowse thimpress / wp_hotel_booking | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWP Hotel Booking < 1.10.4 - PHP Object InjectionCVSS 9.8
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Impact
Unauthenticated attackers can exploit PHP object injection to execute arbitrary code, leading to complete server compromise.
Remediation
Upgrade to WP Hotel Booking version 1.10.3 or later.
Source: ProjectDiscovery