CVE-2024-51582: WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability
Published Nov 4, 2024
·Updated
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.
Affected Software
1 affected component
thimpress Wp Hotel Booking Wordpress<=2.1.4
Event History
Nov 4, 2024
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-51582?
CVE-2024-51582 is classified as a high severity vulnerability due to its potential for PHP Local File Inclusion.
2
How do I fix CVE-2024-51582?
To fix CVE-2024-51582, update the WP Hotel Booking plugin to the latest version beyond 2.1.4.
3
What versions of WP Hotel Booking are affected by CVE-2024-51582?
CVE-2024-51582 affects WP Hotel Booking versions from n/a up to and including 2.1.4.
4
What type of vulnerability is CVE-2024-51582?
CVE-2024-51582 is a Path Traversal vulnerability that allows local file inclusion.
5
Can CVE-2024-51582 be exploited remotely?
Yes, CVE-2024-51582 can potentially be exploited remotely if the plugin is not patched.