WordPress Plugin Vulnerabilities

WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation

Description

The plugin does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.

Proof of Concept

Affects Plugins

Fixed in 2.3.3

References

Miscellaneous

Original Researcher
reconnaissance
Submitter
reconnaissance
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-21 (about 18 days ago)
Added
2026-07-21 (about 17 days ago)
Last Updated
2026-07-21 (about 17 days ago)

Other