CVE-2021-36852: WordPress WP Hotel Booking plugin <= 1.10.5 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36852?
CVE-2021-36852 is a Cross-Site Request Forgery (CSRF) vulnerability in the ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
How severe is CVE-2021-36852?
CVE-2021-36852 has a severity level of high.
What software versions are affected by CVE-2021-36852?
The ThimPress WP Hotel Booking plugin versions up to and including 1.10.5 are affected by CVE-2021-36852.
How can I fix CVE-2021-36852?
To fix CVE-2021-36852, update the ThimPress WP Hotel Booking plugin to version 1.10.6 or later.
Where can I find more information about CVE-2021-36852?
You can find more information about CVE-2021-36852 at the following references: [Patchstack](https://patchstack.com/database/vulnerability/wp-hotel-booking/wordpress-wp-hotel-booking-plugin-1-10-5-cross-site-request-forgery-csrf-vulnerability) and [WordPress Plugin Directory](https://wordpress.org/plugins/wp-hotel-booking/#developers).