CVE-2020-29047: Critical severity thimpress wp hotel booking vulnerability
Published Mar 3, 2021
·Updated
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpresshotelbooking1 cookie in load in includes/class-wphb-sessions.php.
Affected Software
1 affected component
thimpress Wp Hotel Booking Wordpress<=1.10.2
Event History
Mar 3, 2021
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-29047.
2
What is the severity level of CVE-2020-29047?
The severity level of CVE-2020-29047 is critical with a score of 9.8.
3
How does the wp-hotel-booking plugin through 1.10.2 for WordPress allow attackers to execute arbitrary code?
The wp-hotel-booking plugin allows attackers to execute arbitrary code through an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
4
What is the affected software by CVE-2020-29047?
The affected software is the wp-hotel-booking plugin through version 1.10.2 for WordPress.
5
How can I fix the vulnerability CVE-2020-29047?
To fix the vulnerability, update to a version of the wp-hotel-booking plugin that is newer than 1.10.2.