Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP Hotel Booking — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in WP Hotel Booking, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page covers weaknesses in the WP Hotel Booking plugin, a popular WordPress solution developed by a third-party vendor. It is categorized under general software security vulnerabilities affecting content management system extensions. This page collects a comprehensive list of known security flaws, ranging from cross-site scripting and SQL injection to authentication bypasses and insecure direct object references. The data covers reported vulnerabilities from the plugin’s initial release through the most recent updates, ensuring a complete historical perspective on the product’s security posture. By aggregating these findings, we provide a unified view of the risks associated with this specific software component, allowing security professionals to assess the cumulative impact of various exploit vectors over time. Visitors to this page can track the vendor’s advisory history to see how quickly and effectively past issues were addressed. You can also understand the broader context of common weakness classes, such as input validation failures or permission management errors, as they apply to this specific product. Additionally, the page allows you to look up the product’s vulnerability history to identify recurring patterns or persistent weaknesses that may still exist in current versions. This information is essential for developers, security auditors, and site administrators who need to make informed decisions about patching, mitigation, or whether to continue using the software in their environments.

Vendor: ThimPress

CVE IDTitleCVSSSeverityPublished
CVE-2026-15094 WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter CWE-79 6.1 Medium2026-07-17
CVE-2026-11901 WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler CWE-345 5.3 Medium2026-07-11
CVE-2026-11392 WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters CWE-79 6.1 Medium2026-07-10
CVE-2026-9822 WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers --2026-06-19
CVE-2025-14075 WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter CWE-200 5.3 Medium2026-01-17
CVE-2025-63012 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium2025-12-09
CVE-2025-63011 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2025-12-09
CVE-2025-63013 WordPress WP Hotel Booking plugin <= 2.2.7 - Sensitive Data Exposure vulnerability CWE-497 4.3 Medium2025-12-09
CVE-2025-8942 WP Hotel Booking < 2.2.3 - Subscriber+ Rating Manipulation 5.3AIMediumAI2025-09-18
CVE-2025-47448 WordPress WP Hotel Booking plugin <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 4.3 Medium2025-05-07
CVE-2024-13447 WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval CWE-862 4.3 Medium2025-01-22
CVE-2024-12370 WP Hotel Booking <= 2.1.5 - Missing Authorization CWE-284 5.3 Medium2025-01-17
CVE-2024-51582 WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability CWE-35 7.5 High2024-11-04
CVE-2024-7855 WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High2024-10-02
CVE-2024-3605 WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection CWE-89 10.0 Critical2024-06-20
CVE-2024-30508 WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability CWE-862 6.5 Medium2024-03-29
CVE-2023-5651 WP Hotel Booking < 2.0.8 - Subscriber+ Arbitrary Post Deletion 6.5AIMediumAI2023-11-20
CVE-2023-5799 WP Hotel Booking < 2.0.9 - Contributor+ Arbitrary Post Deletion 6.5AIMediumAI2023-11-20
CVE-2023-5652 WP Hotel Booking < 2.0.8 - Unauthenticated SQLi 9.8AICriticalAI2023-11-20
CVE-2020-36757 WP Hotel Booking <= 1.10.1 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium2023-07-12
CVE-2021-36852 WordPress WP Hotel Booking plugin <= 1.10.5 - Cross-Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium2022-08-22

All 21 known CVE vulnerabilities affecting WP Hotel Booking with full Chinese analysis, references, and POCs where available.