Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5652

Опубликовано: 20 нояб. 2023
Источник: nvd
CVSS3: 9.8
EPSS Средний

Описание

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:*
Версия до 2.0.8 (исключая)

EPSS

Процентиль: 96%
0.22573
Средний

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
около 2 лет назад

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

EPSS

Процентиль: 96%
0.22573
Средний

9.8 Critical

CVSS3

Дефекты

CWE-89