Hotel Booking <= 3.8 - Missing Authorization
medium
The Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.8
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-63001 on NVD →
Hotel Booking <= 3.7 - Authenticated (Contributor+) Local File Inclusion
high
The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. Th...
- CVSS:
- 7.5
- Affected:
- up to 3.7
- Fixed in:
- 3.8
- Disclosed:
- Jun 27, 2025
CVE-2025-53259 on NVD →
Hotel Booking <= 3.6 - Authenticated (Contributor+) Local File Inclusion
high
The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion via the nd_booking_ss_rooms() function in versions up to, and including, 3.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execu...
- CVSS:
- 8.8
- Affected:
- up to 3.6
- Fixed in:
- 3.7
- Disclosed:
- May 7, 2025
CVE-2025-47498 on NVD →
Hotel Booking <= 3.6 - Unauthenticated Local File Inclusion
critical
The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls...
- CVSS:
- 9.8
- Affected:
- up to 3.6
- Fixed in:
- 3.7
- Disclosed:
- Apr 17, 2025
CVE-2025-39526 on NVD →
Hotel Booking < 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin < 3.3 at WordPress.
- CVSS:
- 6.4
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- May 26, 2022
CVE-2022-29443 on NVD →
ND Booking <= 2.4 - Unauthenticated Arbitrary Options Update
critical
The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due to missing capability checks and insufficient validation of the options supplied. This makes it possible for unauthenticated attackers to update arbitrary site options that can allow them to escalate...
- CVSS:
- 9.6
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- Aug 5, 2019
CVE-2019-15774 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database