High 7.3 Unfixed
2026-01-22≤ 1.4.2
CVE-2025-69185
Minimum safe version
1.3.7
Update to 1.3.7 or later to address 4 fixable vulnerabilities
CVE-2025-69185
CVE-2025-69056
WordPress Hotel Listing plugin <= 1.4.2 - Broken Access Control vulnerability
CVE-2025-58710
Hotel Listing < 1.3.3 - Authenticated Stored Cross-Site Scripting
WordPress Hotel Listing Plugin < 1.3.7 is vulnerable to Privilege Escalation
Hotel Listings < 1.3.3 - Authenticated Stored Cross-Site Scripting
WordPress Hotel Listing premium plugin <= 1.2.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability