Show filters
56 Total Results
Displaying 11-20 of 56
Sort by:
Attacker Value
Unknown
CVE-2024-4413
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
0
Attacker Value
Unknown
CVE-2024-2749
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.
0
Attacker Value
Unknown
CVE-2024-2441
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
0
Attacker Value
Unknown
CVE-2024-32563
Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VikBooking Hotel Booking Engine & PMS allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.6.7.
0
Attacker Value
Unknown
CVE-2024-30508
Disclosure Date: March 29, 2024 (last updated February 12, 2025)
Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.
0
Attacker Value
Unknown
CVE-2023-5991
Disclosure Date: December 26, 2023 (last updated January 03, 2024)
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server
0
Attacker Value
Unknown
CVE-2023-5799
Disclosure Date: November 20, 2023 (last updated November 28, 2023)
The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them
0
Attacker Value
Unknown
CVE-2023-5652
Disclosure Date: November 20, 2023 (last updated November 28, 2023)
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections
0
Attacker Value
Unknown
CVE-2023-5651
Disclosure Date: November 20, 2023 (last updated November 28, 2023)
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts
0
Attacker Value
Unknown
CVE-2023-28498
Disclosure Date: November 12, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.
0