Thimpress
Thimpress WP Hotel Booking: vulnerabilidades y CVE
Thimpress WP Hotel Booking tiene 26 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses12
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15152 | Media (5.3) | 0.16% | — | 6 ago 2026 | The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total,… |
| CVE-2026-15149 | Media (5.3) | 0.32% | — | 6 ago 2026 | The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing… |
| CVE-2026-15153 | Media (6.8) | 0.39% | — | 30 jul 2026 | The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress… |
| CVE-2026-15464 | Media (6.4) | 0.33% | — | 24 jul 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and… |
| CVE-2026-15094 | Media (6.1) | 0.69% | — | 17 jul 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output… |
| CVE-2026-11901 | Media (5.3) | 0.26% | — | 11 jul 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler… |
| CVE-2026-11392 | Media (6.1) | 0.45% | — | 10 jul 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input… |
| CVE-2026-9822 | Media (6.5) | 0.34% | — | 19 jun 2026 | The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items,… |
| CVE-2025-14075 | Media (5.3) | 0.30% | — | 17 ene 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX… |
| CVE-2025-63013 | Media (4.3) | 0.26% | — | 9 dic 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from… |
| CVE-2025-63012 | Media (4.3) | 0.13% | — | 9 dic 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.8. |
| CVE-2025-63011 | Media (5.9) | 0.20% | — | 9 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a… |
| CVE-2025-8942 | Crítica (9.1) | 0.30% | — | 18 sept 2025 | The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by… |
| CVE-2025-47448 | Media (4.3) | 0.16% | — | 7 may 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9. |
| CVE-2024-13447 | Media (4.3) | 0.36% | — | 22 ene 2025 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This… |
| CVE-2024-12370 | Media (5.3) | 0.32% | — | 17 ene 2025 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for… |
| CVE-2024-51582 | Alta (8.8) | 0.53% | — | 4 nov 2024 | Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9. |
| CVE-2024-7855 | Alta (8.8) | 18% | — | 2 oct 2024 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible… |
| CVE-2024-3605 | Crítica (9.8) | 4.2% | — | 20 jun 2024 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient… |
| CVE-2024-30508 | Crítica (9.8) | 0.52% | — | 29 mar 2024 | Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2. |
| CVE-2023-5799 | Media (5.4) | 0.52% | — | 20 nov 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them |
| CVE-2023-5652 | Crítica (9.8) | 64% | — | 20 nov 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing… |
| CVE-2023-5651 | Media (5.4) | 0.27% | — | 20 nov 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as… |
| CVE-2020-36757 | Media (4.3) | 0.39% | — | 12 jul 2023 | The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item()… |
| CVE-2021-36852 | Alta (8) | 0.39% | — | 22 ago 2022 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress. |
| CVE-2020-29047 | Crítica (9.8) | 16% | — | 3 mar 2021 | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in… |