Vulnerability Description
The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thimpress | Wp Hotel Booking | < 2.0.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/3061f85e-a70e-49e5-bccf-ae9240f51178ExploitThird Party Advisory
- https://wpscan.com/vulnerability/3061f85e-a70e-49e5-bccf-ae9240f51178ExploitThird Party Advisory
FAQ
What is CVE-2023-5799?
CVE-2023-5799 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them
How severe is CVE-2023-5799?
CVE-2023-5799 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5799?
Check the references section above for vendor advisories and patch information. Affected products include: Thimpress Wp Hotel Booking.