cleantalk
Vulnerabilities and Security Researches

WP Hotel Booking, 6a028b01-38e4-4c12-aa19-9a83cf6c1b41

Application

WP Hotel Booking

Published on
-
Research Description
WP Hotel Booking [wp-hotel-booking] < 2.0.9.3 WP Hotel Booking &lt; 2.0.9.3 - Improper Authorization on Multiple REST API Routes The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to an improper capability check on the &#039;pricing_plans&#039;, &#039;block_date&#039;, &#039;manager_bookings&#039;, and &#039;update_field_room&#039; functions for the &#039;pricing-plans&#039;, &#039;block-date&#039;, &#039;manager-bookings&#039;, and &#039;update-field&#039; REST routes, respectively, in versions up to, and including, 2.0.9.2. This makes it possible for unauthenticated attackers to expose sensitive information about bookings or modify them.
Affected versions
max 2.0.9.3.
Status
vulnerable