WP Hotel Booking <= 2.2.1 - Improper Input Validation to Authenticated (Subscriber+) Rating Manipulation
WP Hotel Booking
Minimum safe version
2.3.0
Update to 2.3.0 or later to address 27 fixable vulnerabilities
CVE-2025-14075
CVE-2025-63011
CVE-2025-63012
CVE-2025-63013
CVE-2025-47448
CVE-2024-13447
CVE-2024-12370
CVE-2024-51582
CVE-2024-7855
WP Hotel Booking < 2.0.9.3 - Improper Authorization on Multiple REST API Routes
CVE-2024-3605
CVE-2024-30508
WP Hotel Booking <= 2.0.9.2 - Improper Authorization on Multiple REST API Routes
CVE-2023-5799
CVE-2023-5652
CVE-2023-5651
WP Hotel Booking <= 2.0.7 - Missing Authorization to (Subscriber+) Arbitrary Post Deletion
WP Hotel Booking <= 1.10.5 - Unauthenticated Arbitrary Settings Update
CVE-2020-36757
CVE-2021-4342
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
WP Hotel Booking <= 2.0.0 - Missing Authorization to Settings Update
WordPress WP Hotel Booking plugin <= 1.10.5 - Unauthenticated Arbitrary Settings Update vulnerability
CVE-2021-36852
WordPress WP Hotel Booking plugin <= 1.10.1 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2020-29047