Vulnerabilities > Thimpress > WP Hotel Booking > 2.0.9

DATE CVE VULNERABILITY TITLE RISK
2025-01-17 CVE-2024-12370 Missing Authorization vulnerability in Thimpress WP Hotel Booking
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5.
network
low complexity
thimpress CWE-862
5.3
2024-03-29 CVE-2024-30508 Unspecified vulnerability in Thimpress WP Hotel Booking
Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.
network
low complexity
thimpress
critical
9.8