Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WP Hotel Booking — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in WP Hotel Booking, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the WordPress plugin WP Hotel Booking, a third-party extension that adds hotel reservation functionality to WordPress sites. The collection spans all publicly disclosed weaknesses affecting the plugin, primarily including cross-site scripting (XSS), SQL injection, and broken access control issues. Time coverage extends from the plugin's initial public release through the most recent advisory updates. Readers can use this page to track security advisories issued by the plugin vendor, understand the specific weakness classes (CWE categories) that have historically affected WP Hotel Booking, and review the full vulnerability history for this product. The aggregation is intended for security teams, WordPress site administrators, and developers who need to assess patch status and prioritize remediation efforts for this booking extension.

Vendor: ThimPress

CVE ID Title CVSS Severity Published
CVE-2026-15149 WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation 5.3 Medium 2026-08-06
CVE-2026-15152 WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass 5.3 Medium 2026-08-06
CVE-2026-15153 WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search - - 2026-07-30
CVE-2026-15464 WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute CWE-79 6.4 Medium 2026-07-24
CVE-2026-15094 WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter CWE-79 6.1 Medium 2026-07-17
CVE-2026-11901 WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler CWE-345 5.3 Medium 2026-07-11
CVE-2026-11392 WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters CWE-79 6.1 Medium 2026-07-10
CVE-2026-9822 WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers - - 2026-06-19
CVE-2025-14075 WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter CWE-200 5.3 Medium 2026-01-17
CVE-2025-63012 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-12-09
CVE-2025-63011 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2025-12-09
CVE-2025-63013 WordPress WP Hotel Booking plugin <= 2.2.7 - Sensitive Data Exposure vulnerability CWE-497 4.3 Medium 2025-12-09
CVE-2025-8942 WP Hotel Booking < 2.2.3 - Subscriber+ Rating Manipulation 5.3AI Medium AI 2025-09-18
CVE-2025-47448 WordPress WP Hotel Booking plugin <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 4.3 Medium 2025-05-07
CVE-2024-13447 WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval CWE-862 4.3 Medium 2025-01-22
CVE-2024-12370 WP Hotel Booking <= 2.1.5 - Missing Authorization CWE-284 5.3 Medium 2025-01-17
CVE-2024-51582 WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability CWE-35 7.5 High 2024-11-04
CVE-2024-7855 WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High 2024-10-02
CVE-2024-3605 WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection CWE-89 10.0 Critical 2024-06-20
CVE-2024-30508 WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability CWE-862 6.5 Medium 2024-03-29
CVE-2023-5651 WP Hotel Booking < 2.0.8 - Subscriber+ Arbitrary Post Deletion 6.5AI Medium AI 2023-11-20
CVE-2023-5799 WP Hotel Booking < 2.0.9 - Contributor+ Arbitrary Post Deletion 6.5AI Medium AI 2023-11-20
CVE-2023-5652 WP Hotel Booking < 2.0.8 - Unauthenticated SQLi 9.8AI Critical AI 2023-11-20
CVE-2020-36757 WP Hotel Booking <= 1.10.1 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium 2023-07-12
CVE-2021-36852 WordPress WP Hotel Booking plugin <= 1.10.5 - Cross-Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2022-08-22

All 25 known CVE vulnerabilities affecting WP Hotel Booking with full Chinese analysis, references, and POCs where available.