CVE-2020-29047
WP Hotel Booking <= 1.10.3 - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
El plugin wp-hotel-booking versiones hasta 1.10.2 para WordPress, permite a atacantes remotos ejecutar código arbitrario debido a una operación de deserializar en la cookie thimpress_hotel_booking_1 en la carga en el archivo includes/classwphb-sessions.php
The wp-hotel-booking plugin through 1.10.3 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. This was finally patched in 1.10.04
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-24 CVE Reserved
- 2020-12-08 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/wp-hotel-booking/#developers | Product |
URL | Date | SRC |
---|---|---|
https://appcheck-ng.com/cve-2020-29047 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Thimpress Search vendor "Thimpress" | Wp Hotel Booking Search vendor "Thimpress" for product "Wp Hotel Booking" | <= 1.10.2 Search vendor "Thimpress" for product "Wp Hotel Booking" and version " <= 1.10.2" | wordpress |
Affected
|