cleantalk
Vulnerabilities and Security Researches

WP Hotel Booking, 89e898ab477228014eb91ef45fb9cb1f99fef229

Application

WP Hotel Booking

Published on
Aug 22, 2022
Research Description
WP Hotel Booking [wp-hotel-booking] < 2.0.1 WP Hotel Booking <= 2.0.0 - Missing Authorization to Settings Update The WP Hotel Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on settings update in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to update the plugin's settings.
Affected versions
max 2.0.1.
Status
vulnerable