WordPress Plugin Vulnerabilities
WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
Description
The plugin does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
reconnaissance
Submitter
reconnaissance
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-21 (about 18 days ago)
Added
2026-07-21 (about 17 days ago)
Last Updated
2026-07-21 (about 17 days ago)