CVE-2023-5651: WP Hotel Booking < 2.0.8 - Subscriber+ Arbitrary Post Deletion
Published Nov 20, 2023
·Updated
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts
Affected Software
1 affected component
thimpress Wp Hotel Booking Wordpress<2.0.8
Event History
Nov 20, 2023
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionWeakness
May 24, 57290
Event
via FIRST·01:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-5651?
The severity of CVE-2023-5651 is medium.
2
How does CVE-2023-5651 affect WP Hotel Booking plugin?
CVE-2023-5651 allows any authenticated users, such as subscribers, to delete arbitrary posts in WP Hotel Booking plugin.
3
Is WP Hotel Booking plugin version 2.0.8 affected by CVE-2023-5651?
Yes, WP Hotel Booking plugin version 2.0.8 is affected by CVE-2023-5651.
4
What can an attacker do with CVE-2023-5651?
An attacker can delete arbitrary posts in WP Hotel Booking plugin using CVE-2023-5651.
5
How can I fix CVE-2023-5651?
To fix CVE-2023-5651, update WP Hotel Booking plugin to a version higher than 2.0.8.