CVE Database
/

CVE-2025-8942

Back to search

CVE-2025-8942

Published: Sep 18, 2025

Modified: Sep 22, 2025

PUBLISHED

Description

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

VendorProductVersions

Unknown

WP Hotel Booking

affected
0 - < 2.2.3

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now