VYPR

Wp Hotel Booking

by WordPress

Source repositories

CVEs (27)

  • CVE-2021-36852MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.

  • CVE-2024-13447MedJan 22, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with…

  • CVE-2026-15153MedJul 30, 2026
    risk 0.00cvss 6.8epss 0.00

    The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL…

  • CVE-2026-15464MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15094MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.01

    The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2026-11901MedJul 11, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the…

  • CVE-2026-11392MedJul 10, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for…

Page 2 of 2