Extension WordPress
Vulnérabilités MotoPress Hotel Booking
Cette page rassemble les failles publiées pour MotoPress Hotel Booking, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MotoPress Hotel Booking
6 fiches
MotoPress Hotel Booking <= 6.0.3 – Authenticated (Subscriber+) Information Exposure
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or…
*-6.0.3
6.0.4
01/07/2026
MotoPress Hotel Booking <= 6.0.1 – Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action
The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action.…
*-6.0.1
6.0.2
21/05/2026
Hotel Booking Lite <= 5.2.3 – Authenticated (Hotel Worker+) Remote Code Execution
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with Hotel Worker-level access and above, to execute code on…
*-5.2.3
5.2.4
25/11/2025
Hotel Booking Lite <= 4.11.1 – Unauthenticated PHP Object Injection
The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object.…
*-4.11.1
4.11.2
10/05/2024
Hotel Booking Lite <= 4.8.4 – Insufficient Path Validation to Unauthenticated Arbitrary File Deletion and Download
The Hotel Booking Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the maybeDownload() function and insufficient path validation in all versions up to 4.8.5 (exclusive). This makes it…
[*, 4.8.5)
4.8.5
01/12/2023
Hotel Booking Lite <= 4.6.0 – Cross-Site Request Forgery to Settings Update
The Hotel Booking Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6.0. This is due to missing or incorrect nonce validation on the 'render' and 'onLoad' functions. This makes it…
*-4.6.0
4.7.0
16/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.