The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://wordpress.org/plugins/wp-hotel-booking/#developers | third party advisory product |
https://appcheck-ng.com/cve-2020-29047/ | third party advisory exploit |