Extension WordPress
Vulnérabilités Hotel Booking
Cette page rassemble les failles publiées pour Hotel Booking, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Hotel Booking
6 fiches
Hotel Booking <= 3.8 – Missing Authorization
The Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-3.8
Non indiqué
31/12/2025
Hotel Booking <= 3.7 – Authenticated (Contributor+) Local File Inclusion
The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on…
*-3.7
3.8
27/06/2025
Hotel Booking <= 3.6 – Authenticated (Contributor+) Local File Inclusion
The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion via the nd_booking_ss_rooms() function in versions up to, and including, 3.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…
*-3.6
3.7
07/05/2025
Hotel Booking <= 3.6 – Unauthenticated Local File Inclusion
The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
*-3.6
3.7
17/04/2025
Hotel Booking < 3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin < 3.3 at WordPress.
[*, 3.3)
3.3
26/05/2022
ND Booking <= 2.4 – Unauthenticated Arbitrary Options Update
The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due to missing capability checks and insufficient validation of the options supplied. This makes it possible for unauthenticated attackers…
[*, 2.5)
2.5
05/08/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.