Motopress
Motopress Hotel Booking Lite: vulnerabilidades y CVE
Motopress Hotel Booking Lite tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57347 | Media (6.5) | 0.37% | — | 2 jul 2026 | Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. |
| CVE-2022-50948 | Media (5.1) | 0.19% | — | 10 may 2026 | Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can… |
| CVE-2024-4413 | Crítica (9.8) | 0.85% | — | 14 may 2024 | The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers… |
| CVE-2023-5991 | Crítica (9.8) | 3.3% | — | 26 dic 2023 | The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and… |
| CVE-2023-28498 | Alta (8.8) | 0.31% | — | 12 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions. |