CVE-2026-15464
- EPSS 0.19%
- Veröffentlicht 24.07.2026 06:52:01
- Zuletzt bearbeitet 24.07.2026 20:45:45
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possi...
CVE-2026-15094
- EPSS 0.51%
- Veröffentlicht 17.07.2026 05:35:59
- Zuletzt bearbeitet 17.07.2026 19:17:12
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible...
CVE-2026-11901
- EPSS 0.18%
- Veröffentlicht 11.07.2026 05:35:44
- Zuletzt bearbeitet 14.07.2026 15:16:56
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation...
CVE-2026-11392
- EPSS 0.27%
- Veröffentlicht 10.07.2026 03:31:13
- Zuletzt bearbeitet 14.07.2026 02:16:52
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. ...
CVE-2025-14075
- EPSS 0.27%
- Veröffentlicht 17.01.2026 02:22:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users wit...
CVE-2025-63013
- EPSS 0.25%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 27.04.2026 19:16:17
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.
CVE-2025-63012
- EPSS 0.13%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 27.04.2026 19:16:17
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.
CVE-2025-63011
- EPSS 0.2%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.
CVE-2025-47448
- EPSS 0.16%
- Veröffentlicht 07.05.2025 14:19:34
- Zuletzt bearbeitet 23.04.2026 15:30:14
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9.
CVE-2024-13447
- EPSS 0.36%
- Veröffentlicht 22.01.2025 11:15:07
- Zuletzt bearbeitet 24.01.2025 20:53:40
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenti...