cleantalk
Vulnerabilities and Security Researches

WP Hotel Booking, CVE-2020-29047

CVE, Research URL

CVE-2020-29047

Application

WP Hotel Booking

Published on
Mar 03, 2021
Research Description
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Affected versions
max 1.10.2.
Status
vulnerable