plugin

Nd Booking Vulnerabilities

6 known security issues reported for the Nd Booking WordPress plugin. Most recent disclosed Dec 31, 2025.

2 critical 2 high 2 medium

Running Nd Booking on your site? Check whether your installed version is affected.

Scan your site free

Hotel Booking <= 3.8 - Missing Authorization

medium

The Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.8
Fix:
No patched version reported
Disclosed:
Dec 31, 2025

CVE-2025-63001 on NVD →

Hotel Booking <= 3.7 - Authenticated (Contributor+) Local File Inclusion

high

The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. Th...

CVSS:
7.5
Affected:
up to 3.7
Fixed in:
3.8
Disclosed:
Jun 27, 2025

CVE-2025-53259 on NVD →

Hotel Booking <= 3.6 - Authenticated (Contributor+) Local File Inclusion

high

The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion via the nd_booking_ss_rooms() function in versions up to, and including, 3.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execu...

CVSS:
8.8
Affected:
up to 3.6
Fixed in:
3.7
Disclosed:
May 7, 2025

CVE-2025-47498 on NVD →

Hotel Booking <= 3.6 - Unauthenticated Local File Inclusion

critical

The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls...

CVSS:
9.8
Affected:
up to 3.6
Fixed in:
3.7
Disclosed:
Apr 17, 2025

CVE-2025-39526 on NVD →

Hotel Booking < 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin < 3.3 at WordPress.

CVSS:
6.4
Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
May 26, 2022

CVE-2022-29443 on NVD →

ND Booking <= 2.4 - Unauthenticated Arbitrary Options Update

critical

The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due to missing capability checks and insufficient validation of the options supplied. This makes it possible for unauthenticated attackers to update arbitrary site options that can allow them to escalate...

CVSS:
9.6
Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Aug 5, 2019

CVE-2019-15774 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database