Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical2
High0
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-21

CVE-2024-4413 - Hotel Booking Lite Plugin

The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Hotel Booking Lite

CVE-2024-4413

CRITICAL CVSS 9.8 2024-05-14
Threat Entry Updated 2024-11-21

CVE-2023-5991 - Hotel Booking Lite Plugin

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

PLUGIN Hotel Booking Lite

CVE-2023-5991

CRITICAL CVSS 9.8 2023-12-26
Scroll to top