plugin

Wp Hotel Booking Vulnerabilities

54 known security issues reported for the Wp Hotel Booking WordPress plugin. Most recent disclosed Jul 30, 2026.

3 critical 4 high 21 medium

Running Wp Hotel Booking on your site? Check whether your installed version is affected.

Scan your site free

WP Hotel Booking < 2.3.2 - Authenticated (Custom role+) SQL Injection

medium

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection in versions up to 2.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom role-level access and above, to appen...

CVSS:
6.5
Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Jul 30, 2026

CVE-2026-15153 on NVD →

WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abo...

CVSS:
6.4
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Jul 23, 2026

CVE-2026-15464 on NVD →

Hotel Booking <= 2.3.2 - Unauthenticated Price Manipulation

medium

The Hotel Booking plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 2.3.2. This is due to missing server-side validation of the qty parameter on the public REST API endpoint, allowing non-positive values to manipulate the calculated booking total. This makes it possible for unau...

CVSS:
5.3
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Jul 21, 2026

CVE-2026-15149 on NVD →

WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Jul 16, 2026

CVE-2026-15094 on NVD →

WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the attacker-controlled `$_REQUEST['test_ipn']` paramet...

CVSS:
5.3
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jul 10, 2026

CVE-2026-11901 on NVD →

WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jul 9, 2026

CVE-2026-11392 on NVD →

Hotel Booking <= 2.3.1 - Unauthenticated Payment Bypass

medium

The Hotel Booking plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 2.3.1. This is due to missing validation of the IPN receiver email against the configured merchant PayPal account, allowing spoofed IPN payloads to trigger booking completion without a real payment. This makes it po...

CVSS:
5.3
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jul 9, 2026

CVE-2026-15152 on NVD →

WP Hotel Booking < 2.3.1 - Missing Authorization

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Jun 19, 2026

CVE-2026-9822 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.2.8 (closed)

unknown

[en] The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protec...

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 17, 2026

CVE-2025-14075 on NVD →

WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protection....

CVSS:
5.3
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 16, 2026

CVE-2025-14075 on NVD →

WP Hotel Booking [wp-hotel-booking] <= 2.2.7 (unfixed + closed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63013 on NVD →

WP Hotel Booking [wp-hotel-booking] <= 2.2.7 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63012 on NVD →

WP Hotel Booking [wp-hotel-booking] <= 2.2.7 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63011 on NVD →

Hotel Booking <= 2.2.7 - Unauthenticated Information Exposure

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Nov 5, 2025

CVE-2025-63013 on NVD →

Hotel Booking <= 2.2.8 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
4.4
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Nov 5, 2025

CVE-2025-63011 on NVD →

Hotel Booking <= 2.2.8 - Cross-Site Request Forgery

medium

The Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tri...

CVSS:
4.3
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Nov 5, 2025

CVE-2025-63012 on NVD →

WP Hotel Booking <= 2.2.1 - Improper Input Validation to Authenticated (Subscriber+) Rating Manipulation

medium

The WP Hotel Booking plugin for WordPress is vulnerable to rating manipulation in all versions up to, and including, 2.2.2. This is due to insufficient input validation. This makes it possible for authenticated attackers, with Subscriber-level access and above, to leave negative reviews.

CVSS:
4.3
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Aug 28, 2025

CVE-2025-8942 on NVD →

WP Hotel Booking <= 2.1.9 - Cross-Site Request Forgery

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.9. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can...

CVSS:
4.3
Affected:
up to 2.1.9
Fixed in:
2.2.0
Disclosed:
May 7, 2025

CVE-2025-47448 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.2.0 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
May 7, 2025

CVE-2025-47448 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.1.7 (closed)

unknown

[en] The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retri...

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Jan 22, 2025

CVE-2024-13447 on NVD →

WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve a...

CVSS:
4.3
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Jan 21, 2025

CVE-2024-13447 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.1.6 (closed)

unknown

[en] The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Jan 17, 2025

CVE-2024-12370 on NVD →

WP Hotel Booking <= 2.1.5 - Missing Authorization

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.

CVSS:
5.3
Affected:
up to 2.1.5
Fixed in:
2.1.6
Disclosed:
Jan 16, 2025

CVE-2024-12370 on NVD →

WP Hotel Booking [wp-hotel-booking] <= 2.2.0 (unfixed + closed)

unknown

[en] Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.

Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Nov 4, 2024

CVE-2024-51582 on NVD →

WP Hotel Booking <= 2.2.9 - Authenticated (Contributor+) Local File Inclusion

high

The WP Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those file...

CVSS:
8.8
Affected:
up to 2.2.9
Fixed in:
2.3.0
Disclosed:
Oct 31, 2024

CVE-2024-51582 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.1.3 (closed)

unknown

[en] The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Oct 2, 2024

CVE-2024-7855 on NVD →

WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the...

CVSS:
8.8
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Oct 1, 2024

CVE-2024-7855 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.1.1 (closed)

unknown

[en] The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Jun 20, 2024

CVE-2024-3605 on NVD →

WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection

critical

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...

CVSS:
10
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Jun 19, 2024

CVE-2024-3605 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.0.9.3 (closed)

unknown

[en] Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

Affected:
up to 2.0.9.3
Fixed in:
2.0.9.3
Disclosed:
Mar 29, 2024

CVE-2024-30508 on NVD →

WP Hotel Booking <= 2.0.9.2 - Missing Authorization

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 2.0.9.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.9.2
Fixed in:
2.0.9.3
Disclosed:
Mar 28, 2024

CVE-2024-30508 on NVD →

WP Hotel Booking <= 2.0.9.2 - Improper Authorization on Multiple REST API Routes

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to an improper capability check on the 'pricing_plans', 'block_date', 'manager_bookings', and 'update_field_room' functions for the 'pricing-plans', 'block-date', 'manager-bookings', and 'update-field' RE...

CVSS:
6.5
Affected:
up to 2.0.9.2
Fixed in:
2.0.9.3
Disclosed:
Feb 3, 2024

WP Hotel Booking [wp-hotel-booking] < 2.0.9.3 (closed)

unknown

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to an improper capability check on the 'pricing_plans', 'block_date', 'manager_bookings', and 'update_field_room' functions for the 'pricing-plans', 'block-date', 'manager-bookings', and 'update-field' RE...

Affected:
up to 2.0.9.3
Fixed in:
2.0.9.3
Disclosed:
Feb 3, 2024

WP Hotel Booking [wp-hotel-booking] < 2.0.9 (closed)

unknown

[en] The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Nov 20, 2023

CVE-2023-5799 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.0.8 (closed)

unknown

[en] The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Nov 20, 2023

CVE-2023-5652 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.0.8 (closed)

unknown

[en] The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Nov 20, 2023

CVE-2023-5651 on NVD →

WP Hotel Booking <= 2.0.7 - Unauthenticated SQL Injection

critical

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the '*_ordering' parameter in all versions up to, and including, 2.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...

CVSS:
9.8
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Oct 26, 2023

CVE-2023-5652 on NVD →

WP Hotel Booking <= 2.0.8 - Insufficient Authorization to Unauthorized Post Deletion

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient authorization checks on the tp_extra_package_remove() function hooked via AJAX in all versions up to, and including, 2.0.7. This makes it possible for authenticated attackers, with contributor-level access a...

CVSS:
4.3
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Oct 26, 2023

CVE-2023-5799 on NVD →

WP Hotel Booking <= 2.0.7 - Missing Authorization to (Subscriber+) Arbitrary Post Deletion

medium

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tp_extra_package_remove() function hooked via AJAX in all versions up to, and including, 2.0.7. This makes it possible for authenticated attackers, with subscriber-level access and above...

CVSS:
6.5
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Oct 20, 2023

CVE-2023-5651 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.0.8 (closed)

unknown

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tp_extra_package_remove() function hooked via AJAX in all versions up to, and including, 2.0.7. This makes it possible for authenticated attackers, with subscriber-level access and above...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Oct 20, 2023

WP Hotel Booking [wp-hotel-booking] < 1.10.2 (closed)

unknown

[en] The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request...

Affected:
up to 1.10.2
Fixed in:
1.10.2
Disclosed:
Jul 12, 2023

CVE-2020-36757 on NVD →

WP Hotel Booking [wp-hotel-booking] < 1.10.2 (closed)

unknown
Affected:
up to 1.10.2
Fixed in:
1.10.2
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

WP Hotel Booking [wp-hotel-booking] < 2.0.1 (closed)

unknown

Unauthenticated Arbitrary Settings Update vulnerability discovered by WPScan in WordPress WP Hotel Booking plugin (versions <= 1.10.5). Deactivate and delete. This plugin has been closed as of 22. august, 2022 and is not available for download. This closure is temporary, pending a full review.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Aug 23, 2022

WP Hotel Booking <= 2.0.0 - Missing Authorization to Settings Update

high

The WP Hotel Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on settings update in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to update the plugin's settings.

CVSS:
7.5
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Aug 22, 2022

WP Hotel Booking [wp-hotel-booking] < 2.0.1 (closed)

unknown

The WP Hotel Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on settings update in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to update the plugin's settings.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Aug 22, 2022

WP Hotel Booking [wp-hotel-booking] < 1.10.6 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.

Affected:
up to 1.10.6
Fixed in:
1.10.6
Disclosed:
Aug 22, 2022

CVE-2021-36852 on NVD →

WP Hotel Booking <= 1.10.5 - Cross-Site Request Forgery

high

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.5 due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to trigger actions via forged request granted they can trick a site administrator into perform...

CVSS:
8.8
Affected:
up to 1.10.5
Fixed in:
1.10.6
Disclosed:
Aug 2, 2022

CVE-2021-36852 on NVD →

WP Hotel Booking [wp-hotel-booking] < 1.10.4 (closed)

unknown

[en] The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

Affected:
up to 1.10.4
Fixed in:
1.10.4
Disclosed:
Mar 3, 2021

CVE-2020-29047 on NVD →

WP Hotel Booking <= 1.10.3 - Remote Code Execution

critical

The wp-hotel-booking plugin through 1.10.3 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. This was finally patched in 1.10.04

CVSS:
9.8
Affected:
up to 1.10.3
Fixed in:
1.10.4
Disclosed:
Dec 8, 2020

CVE-2020-29047 on NVD →

WP Hotel Booking <= 1.10.1 - Cross-Site Request Forgery Bypass

medium

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request gran...

CVSS:
4.3
Affected:
up to 1.10.2
Fixed in:
1.10.2
Disclosed:
Sep 16, 2020

CVE-2020-36757 on NVD →

WP Hotel Booking [wp-hotel-booking] < 1.10.2 (closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress WP Hotel Booking plugin (versions <= 1.10.1).

Affected:
up to 1.10.2
Fixed in:
1.10.2
Disclosed:
Sep 16, 2020

WP Hotel Booking [wp-hotel-booking] < 2.0.1 (closed)

unknown

The plugin does not have authorisation and CSRF checsk in place when updating its settings, which could allow unauthenticated attackers to change them

Affected:
up to 2.0.1
Fixed in:
2.0.1

WP Hotel Booking [wp-hotel-booking] < 1.10.2 (closed)

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 1.10.2
Fixed in:
1.10.2

WP Hotel Booking [wp-hotel-booking] < 2.0.9.3 (closed)

unknown

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to an improper capability check on the &#039;pricing_plans&#039;, &#039;block_date&#039;, &#039;manager_bookings&#039;, and &#039;update_field_room&#039; functions for the &#039;pricing-plans&#039;, &#039...

Affected:
up to 2.0.9.3
Fixed in:
2.0.9.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database