CVE-2023-5991: Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5991?
CVE-2023-5991 has been classified with a high severity due to its potential for unauthorized file access and manipulation.
How do I fix CVE-2023-5991?
To fix CVE-2023-5991, update the Hotel Booking Lite WordPress plugin to version 4.8.5 or later.
What are the risks associated with CVE-2023-5991?
The risks include unauthorized download and deletion of arbitrary files, which could lead to data loss or server compromise.
Who is affected by CVE-2023-5991?
CVE-2023-5991 affects users of the Hotel Booking Lite WordPress plugin versions prior to 4.8.5.
Is CVE-2023-5991 related to user input validation?
Yes, CVE-2023-5991 is related to insufficient validation of file paths provided via user input.