Skip to content

Known CVE

WP Hotel Booking < 1.10.4 - PHP Object Injection

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

CVE-2020-29047

Critical2020CVSS 9.8CWE-502

cve2020 · wordpress · wp-plugin · wp · wp-hotel-booking · rce · thimpress · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website