Impact
The WP Hotel Booking plugin of PayPal instant payment notifications in all versions through 2.3.1 fails to validate the source of the IPN correctly, allows the attacker‑controlled request parameter to select the verification endpoint, and ignores critical checks on receiver email, currency, and transaction ID uniqueness after PayPal returns a VERIFIED status. This flaw enables unauthenticated attackers to make a hotel booking appear paid without submitting real payment, either by using a PayPal sandbox account to receive a VERIFIED response from an attacker’s own PayPal account, or by replaying a previously verified IPN from a nominal payment to an attacker-controlled PayPal account.
Affected Systems
The affected product is thimpress WP Hotel Booking, a WordPress plugin, in all releases up to and including version 2.3.1. Any WordPress site running these versions of the plugin is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and an EPSS score of <1%, indicating a low probability of exploitation at present. It is not listed in the CISA KEV catalog. Exploitation requires only that the site run an unpatched instance of the plugin; no site credentials or special configuration are needed. The most likely vector is the external PayPal IPN system sending notifications to the site, which an attacker can influence through a sandbox or replayed message.
OpenCVE Enrichment