PT-2025-38300 · WordPress · Wp Hotel Booking

CVE-2025-8942

·

Published

2025-09-18

·

Updated

2025-09-18

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WP Hotel Booking WordPress plugin versions prior to 2.2.3
Description The WP Hotel Booking WordPress plugin does not perform adequate server-side validation of review ratings. This allows an attacker to modify the rating value by intercepting and altering requests, potentially submitting negative or out-of-range values.
Recommendations Update WP Hotel Booking WordPress plugin to version 2.2.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-8942

Affected Products

Wp Hotel Booking