This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A critical SQL Injection (SQLi) flaw in WP Hotel Booking. <br>๐ **Consequences**: Attackers can steal, modify, or delete database content.โฆ
๐ข **Affected Product**: WordPress Plugin: **WP Hotel Booking**. <br>๐ฆ **Version**: Versions **before 2.0.8**. <br>โ ๏ธ **Note**: If you are running 2.0.8 or later, you are safe.
Q4What can hackers do? (Privileges/Data)
๐ป **Attacker Capabilities**: <br>โข Execute arbitrary SQL commands. <br>โข Access sensitive user data (credentials, emails). <br>โข Modify site content. <br>โข Potentially take over the database.โฆ
๐ **Threshold**: **Extremely Low**. <br>๐ **Auth**: None required. <br>โ๏ธ **Config**: Default installation is vulnerable. <br>๐ฏ **Ease**: Any internet user can trigger the exploit via the `admin_init` hook.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exploit**: **YES**. <br>๐ **PoC Available**: Proof of Concept exists in Nuclei templates (ProjectDiscovery).โฆ
๐ **Self-Check**: <br>1. Check your WordPress Dashboard for **WP Hotel Booking**. <br>2. Verify the version number. <br>3. If it is < 2.0.8, you are vulnerable.โฆ
โ **Official Fix**: **YES**. <br>๐ **Patch**: Update **WP Hotel Booking** to version **2.0.8** or higher. <br>๐ข **Source**: Vendor (WP Hotel Booking) released the fix. Check WPScan for official advisory.
Q9What if no patch? (Workaround)
๐ง **No Patch Workaround**: <br>1. **Disable Plugin**: Deactivate WP Hotel Booking immediately if you can't update. <br>2. **WAF Rules**: Block requests targeting `admin_init` with suspicious SQL payloads. <br>3.โฆ