WP Hotel Booking

Information

Software Type Plugin
Software Slug wp-hotel-booking (view on wordpress.org)
Software Status Active
Software Author thimpress
Software Website thimpress.com
Software Downloads 452,328
Software Active Installs 7,000
Software Record Last Updated August 19, 2026

Showing 1-20 of 26 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
WP Hotel Booking < 2.3.2 - Authenticated (Custom role+) SQL Injection Patched CVE-2026-15153 6.5 Mokksh Parekh July 30, 2026
WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute Patched CVE-2026-15464 6.4 Wordfence PRISM July 23, 2026
WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter Patched CVE-2026-15094 6.1 Wordfence PRISM July 16, 2026
WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler Patched CVE-2026-11901 5.3 valent1 July 10, 2026
WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters Patched CVE-2026-11392 6.1 1M4 July 9, 2026
WP Hotel Booking < 2.3.1 - Missing Authorization Patched CVE-2026-9822 4.3 Sanjorn Keeratirungsan June 19, 2026
WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter Patched CVE-2025-14075 5.3 Itthidej Aramsri (Boeing777) January 16, 2026
Hotel Booking <= 2.2.7 - Unauthenticated Information Exposure Patched CVE-2025-63013 5.3 daroo November 5, 2025
Hotel Booking <= 2.2.8 - Authenticated (Editor+) Stored Cross-Site Scripting Patched CVE-2025-63011 4.4 daroo November 5, 2025
Hotel Booking <= 2.2.8 - Cross-Site Request Forgery Patched CVE-2025-63012 4.3 daroo November 5, 2025
WP Hotel Booking <= 2.2.1 - Improper Input Validation to Authenticated (Subscriber+) Rating Manipulation Patched CVE-2025-8942 4.3 Muhammed Çelik August 28, 2025
WP Hotel Booking <= 2.1.9 - Cross-Site Request Forgery Patched CVE-2025-47448 4.3 lucky_buddy May 7, 2025
WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval Patched CVE-2024-13447 4.3 Krzysztof Zając January 21, 2025
WP Hotel Booking <= 2.1.5 - Missing Authorization Patched CVE-2024-12370 5.3 Thanh Nam Tran January 16, 2025
WP Hotel Booking <= 2.2.9 - Authenticated (Contributor+) Local File Inclusion Patched CVE-2024-51582 8.8 ghsinfosec October 31, 2024
WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload Patched CVE-2024-7855 8.8 Truoc Phan October 1, 2024
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection Patched CVE-2024-3605 10.0 Krzysztof Zając June 19, 2024
WP Hotel Booking <= 2.0.9.2 - Missing Authorization Patched CVE-2024-30508 5.3 beluga March 28, 2024
WP Hotel Booking <= 2.0.9.2 - Improper Authorization on Multiple REST API Routes Patched 6.5 February 3, 2024
WP Hotel Booking <= 2.0.8 - Insufficient Authorization to Unauthorized Post Deletion Patched CVE-2023-5799 4.3 Erwan LR October 26, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation