CVE-2020-29047
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 16%
from disclosure to weapon
Published on NVDMar 3
VulnCheck+167d
exploitation probability
16%top 3% of all CVEs
observed exploitation
yesVulnCheck
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Affected products
n/a · n/a