Vulnerability Description
The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.
CVSS Score
CRITICAL
References
- https://wpscan.com/vulnerability/d89bb3b2-40ad-4c4f-9f17-4ccacc0f6e1a/
- https://wpscan.com/vulnerability/d89bb3b2-40ad-4c4f-9f17-4ccacc0f6e1a/
FAQ
What is CVE-2025-8942?
CVE-2025-8942 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range v...
How severe is CVE-2025-8942?
CVE-2025-8942 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-8942?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.