WP Hotel Booking, CVE-2025-8942
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 18, 2025
- Research Description
- The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.
- Affected versions
-
max 2.2.3.
- Status
-
vulnerable