VendorsThimPresswp_hotel_bookingany version
Vulnerabilities

ThimPress WP Hotel Booking any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-3605
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
Published 2024-06-20 · Modified
10.0EPSS 0.042
CVE-2023-5652
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
Published 2023-11-20 · Modified
9.8EPSS 0.637
CVE-2020-29047
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Published 2021-03-03 · Modified
9.8EPSS 0.160
CVE-2024-30508
WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability
Published 2024-03-29 · Modified
9.8EPSS 0.005
CVE-2024-7855
WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload
Published 2024-10-02 · Analyzed
8.8EPSS 0.177
CVE-2024-51582
WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability
Published 2024-11-04 · Modified
8.8EPSS 0.005
CVE-2021-36852
WordPress WP Hotel Booking plugin <= 1.10.5 - Cross-Site Request Forgery (CSRF) vulnerability
Published 2022-08-22 · Modified
8.0EPSS 0.004
CVE-2023-5799
WP Hotel Booking < 2.0.9 - Contributor+ Arbitrary Post Deletion
Published 2023-11-20 · Modified
5.4EPSS 0.005
CVE-2023-5651
WP Hotel Booking < 2.0.8 - Subscriber+ Arbitrary Post Deletion
Published 2023-11-20 · Modified
5.4EPSS 0.003
CVE-2024-12370
WP Hotel Booking <= 2.1.5 - Missing Authorization
Published 2025-01-17 · Analyzed
5.3EPSS 0.003
CVE-2020-36757
WP Hotel Booking <= 1.10.1 - Cross-Site Request Forgery Bypass
Published 2023-07-12 · Modified
4.3EPSS 0.004
CVE-2024-13447
WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval
Published 2025-01-22 · Analyzed
4.3EPSS 0.004