CVE-2024-30508
- EPSS 0.24%
- Veröffentlicht 29.03.2024 15:15:14
- Zuletzt bearbeitet 11.02.2025 16:08:21
Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.
CVE-2023-5799
- EPSS 0.05%
- Veröffentlicht 20.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:42:30
The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them
CVE-2023-5652
- EPSS 27.62%
- Veröffentlicht 20.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:42:11
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL...
CVE-2023-5651
- EPSS 0.04%
- Veröffentlicht 20.11.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:42:11
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts
CVE-2020-36757
- EPSS 0.11%
- Veröffentlicht 12.07.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 05:30:14
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for un...
- EPSS 0.1%
- Veröffentlicht 22.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:14:11
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
CVE-2020-29047
- EPSS 84.62%
- Veröffentlicht 03.03.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:23:35
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.