CVE-2025-14075
- EPSS 0.06%
- Veröffentlicht 17.01.2026 02:22:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users wit...
CVE-2025-63013
- EPSS 0.05%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.
CVE-2025-63012
- EPSS 0.03%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.
CVE-2025-63011
- EPSS 0.06%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.
CVE-2025-47448
- EPSS 0.05%
- Veröffentlicht 07.05.2025 14:19:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9.
CVE-2024-13447
- EPSS 0.28%
- Veröffentlicht 22.01.2025 11:15:07
- Zuletzt bearbeitet 24.01.2025 20:53:40
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenti...
CVE-2024-12370
- EPSS 0.34%
- Veröffentlicht 17.01.2025 09:15:07
- Zuletzt bearbeitet 11.02.2025 21:42:23
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add ...
CVE-2024-51582
- EPSS 1.66%
- Veröffentlicht 04.11.2024 14:15:16
- Zuletzt bearbeitet 01.04.2026 16:19:22
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.
CVE-2024-7855
- EPSS 62.9%
- Veröffentlicht 02.10.2024 05:15:11
- Zuletzt bearbeitet 11.02.2025 21:42:45
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, wit...
CVE-2024-3605
- EPSS 81.43%
- Veröffentlicht 20.06.2024 02:15:10
- Zuletzt bearbeitet 08.04.2026 18:21:28
The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied ...