Access violation vulnerability in Hotel Booking Lite 4.8.5

The Hotel Booking Lite plugin for WordPress can be modified by unauthorized individuals. This is because there is a missing check to make sure the user has the right permissions and the plugin does not properly validate file paths. This vulnerability exists in all versions up to 4.8.5 (exclusive). This means that someone without proper authentication can access and delete any files they want, which can lead to remote code execution.

Detected in:

Hotel Booking Lite fixed vulnerable versions: >= * < 4.8.5
MotoPress Hotel Booking fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.