Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10
Critical3
High1
Medium6
Reset
Showing 1-10 of 10 records
Threat Entry Updated 2026-01-26

CVE-2025-14075 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protection. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including full names, addresses, phone numbers, and email addresses by providing a valid email address and a publicly accessible nonce.

PLUGIN Wp Hotel Booking

CVE-2025-14075

MEDIUM CVSS 5.3 2026-01-17
Threat Entry Updated 2025-09-22

CVE-2025-8942 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

PLUGIN Wp Hotel Booking

CVE-2025-8942

CRITICAL CVSS 9.1 2025-09-18
Threat Entry Updated 2025-01-24

CVE-2024-13447 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve a list of registered user emails.

PLUGIN Wp Hotel Booking

CVE-2024-13447

MEDIUM CVSS 4.3 2025-01-22
Threat Entry Updated 2025-02-11

CVE-2024-12370 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.

PLUGIN Wp Hotel Booking

CVE-2024-12370

MEDIUM CVSS 5.3 2025-01-17
Threat Entry Updated 2025-02-11

CVE-2024-7855 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wp Hotel Booking

CVE-2024-7855

HIGH CVSS 8.8 2024-10-02
Threat Entry Updated 2024-11-21

CVE-2024-3605 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Hotel Booking

CVE-2024-3605

CRITICAL CVSS 10.0 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2023-5652 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

PLUGIN Wp Hotel Booking

CVE-2023-5652

CRITICAL CVSS 9.8 2023-11-20
Threat Entry Updated 2024-11-21

CVE-2023-5799 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

PLUGIN Wp Hotel Booking

CVE-2023-5799

MEDIUM CVSS 5.4 2023-11-20
Threat Entry Updated 2024-11-21

CVE-2023-5651 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

PLUGIN Wp Hotel Booking

CVE-2023-5651

MEDIUM CVSS 5.4 2023-11-20
Scroll to top