← back
CVE-2023-5652

WP Hotel Booking < 2.0.8 - Unauthenticated SQLi

EPSS 63.7%
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →