ZeroHour

CVE-2023-5991

PoC
CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

Vendors
motopress
Products
hotel booking lite
Ecosystems
WordPress
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.