WordPress Plugin Vulnerabilities

WP Hotel Booking < 2.2.3 - Subscriber+ Rating Manipulation

Description

The plugin lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

Proof of Concept

Affects Plugins

Fixed in 2.2.3

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Submitter
Muhammed Çelik
Verified
Yes

Timeline

Publicly Published
2025-08-28 (about 4 months ago)
Added
2025-08-28 (about 4 months ago)
Last Updated
2025-08-28 (about 4 months ago)

Other