Description
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server
Published: 2023-12-26
Score: 9.8 Critical
EPSS: 75.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Motopress Hotel Booking Lite
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-02T08:14:25.157Z

Reserved: 2023-11-07T14:37:12.864Z

Link: CVE-2023-5991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-26T19:15:08.213

Modified: 2024-11-21T08:42:56.233

Link: CVE-2023-5991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses