Skip to content

Known CVE

WP Hotel Booking <= 2.0.7 - SQL Injection

WP Hotel Booking WordPress plugin before 2.0.8 contains a SQL injection caused by lack of authorization, CSRF checks, and input escaping in a function hooked to admin_init, letting unauthenticated users perform SQL injections, exploit requires no authentication.

CVE-2023-5652

Critical2023CVSS 9.8CWE-89

cve2023 · wordpress · wp · wp-plugin · sqli · wp-hotel-booking · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website