WP Hotel Booking
cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:wordpress:*:*
- <= 2.1.5
A vulnerability exists in the WP Hotel Booking plugin for WordPress, in all versions through 2.1.5. The issue arises from a lack of proper capability checks, which allows unauthorized users to add rooms with custom prices. This vulnerability could be exploited by unauthenticated attackers to manipulate room data.
Exploitation of this vulnerability could lead to unauthorized modifications of room data, including the addition of rooms with custom prices.
Users are advised to update the WP Hotel Booking plugin to version 2.1.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.