Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 3.3%
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server
Affected products
Unknown · Hotel Booking Lite