Vulnerabilities and security researches fornd-booking nd-booking
Direction: ascendingJun 07, 2024
Hotel Booking # CVE-2019-15774
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 29, 2019
- Research Description
- The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Hotel Booking # CVE-2022-29443
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 16, 2022
- Research Description
- Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 19, 2025
Hotel Booking # CVE-2025-39526
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 17, 2025
- Research Description
- Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking allows PHP Local File Inclusion. This issue affects Hotel Booking: from n/a through 3.6.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable