VYPR

Hotel Booking Lite

by WordPress

CVEs (5)

  • CVE-2024-4413CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in…

  • CVE-2023-5991CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.03

    The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

  • CVE-2025-66078CriDec 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3.

  • CVE-2023-28498MedNov 12, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.

  • CVE-2026-57347MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.