Back

CRITICAL

WP Hotel Booking < 2.0.8 - Unauthenticated SQLi

Published Nov 20, 2023

Description

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Nov 20, 2023
Updated Aug 2, 2024
Reserved Oct 19, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a