Thimpress

Wp Hotel Booking

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 17.01.2025 09:15:07
  • Zuletzt bearbeitet 11.02.2025 21:42:23

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add ...

  • EPSS 0.53%
  • Veröffentlicht 04.11.2024 14:15:16
  • Zuletzt bearbeitet 23.04.2026 15:20:12

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

  • EPSS 17.61%
  • Veröffentlicht 02.10.2024 05:15:11
  • Zuletzt bearbeitet 11.02.2025 21:42:45

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, wit...

  • EPSS 4.19%
  • Veröffentlicht 20.06.2024 02:15:10
  • Zuletzt bearbeitet 08.04.2026 18:21:28

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied ...

  • EPSS 0.52%
  • Veröffentlicht 29.03.2024 15:15:14
  • Zuletzt bearbeitet 28.04.2026 19:24:07

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 20.11.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:42:30

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

Exploit
  • EPSS 63.71%
  • Veröffentlicht 20.11.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:42:11

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 20.11.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:42:11

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

  • EPSS 0.39%
  • Veröffentlicht 12.07.2023 07:15:09
  • Zuletzt bearbeitet 08.04.2026 19:17:38

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for un...

  • EPSS 0.39%
  • Veröffentlicht 22.08.2022 15:15:13
  • Zuletzt bearbeitet 21.11.2024 06:14:11

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.