Extension WordPress
Vulnérabilités WP Hotel Booking, page 2
Cette page rassemble les failles publiées pour WP Hotel Booking, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Hotel Booking
24 fiches
WP Hotel Booking <= 2.0.0 – Missing Authorization to Settings Update
The WP Hotel Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on settings update in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to update the…
*-2.0.0
2.0.1
22/08/2022
WP Hotel Booking <= 1.10.5 – Cross-Site Request Forgery
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.5 due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to trigger actions via…
*-1.10.5
1.10.6
02/08/2022
WP Hotel Booking <= 1.10.3 – Remote Code Execution
The wp-hotel-booking plugin through 1.10.3 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. This was finally patched in 1.10.04
*-1.10.3
1.10.4
08/12/2020
WP Hotel Booking <= 1.10.1 – Cross-Site Request Forgery Bypass
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for…
[*, 1.10.2)
1.10.2
16/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.