The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-12-26T18:33:14.275Z

Updated: 2024-08-02T08:14:25.157Z

Reserved: 2023-11-07T14:37:12.864Z

Link: CVE-2023-5991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-26T19:15:08.213

Modified: 2024-01-02T20:49:50.667

Link: CVE-2023-5991

cve-icon Redhat

No data.