WP Hotel Booking WordPress plugin before 2.0.8 contains a SQL injection caused by lack of authorization, CSRF checks, and input escaping in a function hooked to admin_init, letting unauthenticated users perform SQL injections, exploit requires no authentication.
id: CVE-2023-5652
info:
name: WP Hotel Booking <= 2.0.7 - SQL Injection
author: Shivam Kamboj
...