PT-2023-32336 · WordPress · Wp Hotel Booking

Erwan Lr

·

Published

2023-11-20

·

Updated

2023-11-27

·

CVE-2023-5799

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Hotel Booking WordPress plugin versions prior to 2.0.8
Description The issue concerns a lack of proper authorization in the deletion of packages. This allows users with Contributor and above roles to delete posts that do not belong to them.
Recommendations For versions prior to 2.0.8, update to version 2.0.8 or later to resolve the issue.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-5799

Affected Products

Wp Hotel Booking