Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14
Critical3
High1
Medium10
Reset
Showing 1-14 of 14 records
Threat Entry Updated 2026-07-17

CVE-2026-15094 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Hotel Booking

CVE-2026-15094

MEDIUM CVSS 6.1 2026-07-17
Threat Entry Updated 2026-07-14

CVE-2026-11901 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the attacker-controlled `$_REQUEST['test_ipn']` parameter, force-upgrading any `pending` transaction to `completed` when `test_ipn=1`, and omitting post-verification checks on `receiver_email`, `mc_currency`, and `txn_id` uniqueness after receiving a `VERIFIED` response from PayPal. This makes it possible for unauthenticated attackers to mark arbitrary hotel bookings as fully paid without submitting genuine payment to the merchant — either…

PLUGIN Wp Hotel Booking

CVE-2026-11901

MEDIUM CVSS 5.3 2026-07-11
Threat Entry Updated 2026-07-14

CVE-2026-11392 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Hotel Booking

CVE-2026-11392

MEDIUM CVSS 6.1 2026-07-10
Threat Entry Updated 2026-06-22

CVE-2026-9822 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.

PLUGIN Wp Hotel Booking

CVE-2026-9822

MEDIUM CVSS 6.5 2026-06-19
Threat Entry Updated 2026-01-26

CVE-2025-14075 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protection. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including full names, addresses, phone numbers, and email addresses by providing a valid email address and a publicly accessible nonce.

PLUGIN Wp Hotel Booking

CVE-2025-14075

MEDIUM CVSS 5.3 2026-01-17
Threat Entry Updated 2025-09-22

CVE-2025-8942 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

PLUGIN Wp Hotel Booking

CVE-2025-8942

CRITICAL CVSS 9.1 2025-09-18
Threat Entry Updated 2025-01-24

CVE-2024-13447 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve a list of registered user emails.

PLUGIN Wp Hotel Booking

CVE-2024-13447

MEDIUM CVSS 4.3 2025-01-22
Threat Entry Updated 2025-02-11

CVE-2024-12370 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.

PLUGIN Wp Hotel Booking

CVE-2024-12370

MEDIUM CVSS 5.3 2025-01-17
Threat Entry Updated 2025-02-11

CVE-2024-7855 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wp Hotel Booking

CVE-2024-7855

HIGH CVSS 8.8 2024-10-02
Threat Entry Updated 2024-11-21

CVE-2024-3605 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Hotel Booking

CVE-2024-3605

CRITICAL CVSS 10.0 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2023-5652 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

PLUGIN Wp Hotel Booking

CVE-2023-5652

CRITICAL CVSS 9.8 2023-11-20
Threat Entry Updated 2024-11-21

CVE-2023-5799 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

PLUGIN Wp Hotel Booking

CVE-2023-5799

MEDIUM CVSS 5.4 2023-11-20
Threat Entry Updated 2024-11-21

CVE-2023-5651 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

PLUGIN Wp Hotel Booking

CVE-2023-5651

MEDIUM CVSS 5.4 2023-11-20
Scroll to top