CVE-2024-13447: WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotelbookingloadorderuser AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve a list of registered user emails.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13447?
CVE-2024-13447 is rated as a high severity vulnerability due to the potential for unauthorized data access.
How do I fix CVE-2024-13447?
To fix CVE-2024-13447, update the WP Hotel Booking plugin to version 2.1.7 or later.
Who is affected by CVE-2024-13447?
All users of the WP Hotel Booking plugin for WordPress versions up to and including 2.1.6 are affected by CVE-2024-13447.
What type of vulnerability is CVE-2024-13447?
CVE-2024-13447 is an authorization vulnerability that allows unauthorized access to sensitive data.
Can authenticated attackers exploit CVE-2024-13447?
Yes, authenticated attackers with Subscriber-level access can exploit CVE-2024-13447 to access restricted data.