plugin

Js Multihotel Vulnerabilities

12 known security issues reported for the Js Multihotel WordPress plugin. Most recent disclosed May 15, 2015.

4 medium

Running Js Multihotel on your site? Check whether your installed version is affected.

Scan your site free

Js Multi Hotel [js-multihotel] < 2.2.2

unknown

This plugins is prone to a remote file inclusion vulnerability via includes/show_image.php file parameter. Update the plugin.

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
May 15, 2015

Js Multi Hotel [js-multihotel] < 2.2.2

unknown

This plugin is prone to a full path disclosure vulnerability in includes/timthumb.php src parameter. Update the plugin.

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
May 15, 2015

Js Multi Hotel [js-multihotel] <= 2.2.1 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jan 13, 2015

CVE-2014-100008 on NVD →

Js Multi Hotel [js-multihotel] <= 2.2.1 (closed)

unknown

[en] The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7) p...

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jan 13, 2015

CVE-2014-100009 on NVD →

Js Multi Hotel [js-multihotel] <= 2.2.1 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter.

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jan 9, 2015

CVE-2013-7419 on NVD →

JS Multi Hotel <= 2.2.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

CVSS:
6.1
Affected:
up to 2.2.1
Fix:
No patched version reported
Disclosed:
Mar 31, 2014

CVE-2014-100008 on NVD →

JS Multi Hotel <= 2.2.1 - Full Path Disclosure

medium

The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7) phpthu...

CVSS:
5.3
Affected:
up to 2.2.1
Fix:
No patched version reported
Disclosed:
Mar 31, 2014

CVE-2014-100009 on NVD →

JS Multi Hotel <= 2.2.1 - Reflected Cross-Site Scripting

medium

The JS Multi Hotel Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 2.2.1
Fix:
No patched version reported
Disclosed:
Mar 29, 2014

Js Multi Hotel [js-multihotel] <= 2.2.1 (unfixed)

unknown

The JS Multi Hotel Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 2.2.1
Fix:
No patched version reported
Disclosed:
Mar 29, 2014

JS MultiHotel <= 2.2.1 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter.

CVSS:
6.1
Affected:
up to 2.2.1
Fix:
No patched version reported
Disclosed:
Dec 1, 2013

CVE-2013-7419 on NVD →

Js Multi Hotel [js-multihotel] <= 2.2.1 (unfixed)

unknown

The js-multihotel WordPress plugin was affected by an includes/show_image.php file Parameter Remote File Inclusion DoS security vulnerability.

Affected:
up to 2.2.1
Fix:
No patched version reported

Js Multi Hotel [js-multihotel] <= 2.2.1 (unfixed)

unknown

The js-multihotel WordPress plugin was affected by an includes/timthumb.php src Parameter Direct Request Path Disclosure security vulnerability.

Affected:
up to 2.2.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database