Thimpress

Wp Hotel Booking

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 24.07.2026 06:52:01
  • Zuletzt bearbeitet 24.07.2026 20:45:45

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possi...

  • EPSS 0.51%
  • Veröffentlicht 17.07.2026 05:35:59
  • Zuletzt bearbeitet 17.07.2026 19:17:12

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible...

  • EPSS 0.18%
  • Veröffentlicht 11.07.2026 05:35:44
  • Zuletzt bearbeitet 14.07.2026 15:16:56

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation...

  • EPSS 0.27%
  • Veröffentlicht 10.07.2026 03:31:13
  • Zuletzt bearbeitet 14.07.2026 02:16:52

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. ...

  • EPSS 0.27%
  • Veröffentlicht 17.01.2026 02:22:30
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users wit...

  • EPSS 0.25%
  • Veröffentlicht 09.12.2025 14:52:27
  • Zuletzt bearbeitet 27.04.2026 19:16:17

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

  • EPSS 0.13%
  • Veröffentlicht 09.12.2025 14:52:27
  • Zuletzt bearbeitet 27.04.2026 19:16:17

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.

  • EPSS 0.2%
  • Veröffentlicht 09.12.2025 14:52:27
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.

  • EPSS 0.16%
  • Veröffentlicht 07.05.2025 14:19:34
  • Zuletzt bearbeitet 23.04.2026 15:30:14

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9.

  • EPSS 0.36%
  • Veröffentlicht 22.01.2025 11:15:07
  • Zuletzt bearbeitet 24.01.2025 20:53:40

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenti...