Vulnerability Description
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avirato | Hotels Online Booking Engine | <= 5.0.5 |
References
- https://wpscan.com/vulnerability/03d061b4-1b71-44f5-b3dc-f82a5fcd92ebExploit
- https://wpscan.com/vulnerability/03d061b4-1b71-44f5-b3dc-f82a5fcd92ebExploit
FAQ
What is CVE-2023-0768?
CVE-2023-0768 is a vulnerability with a CVSS score of 8.8 (HIGH). The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authen...
How severe is CVE-2023-0768?
CVE-2023-0768 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0768?
Check the references section above for vendor advisories and patch information. Affected products include: Avirato Hotels Online Booking Engine.