Executive brief
WP Hotel Booking is a WordPress plugin used to manage hotel reservations and room listings. A security flaw in the booking management interface allows authorized staff members, such as booking editors or hotel managers, to execute unauthorized database commands. This could lead to the theft of sensitive customer information, modification of booking records, or full compromise of the website's database.
Technical details
A SQL injection vulnerability exists in the WP Hotel Booking plugin for WordPress due to insufficient sanitization and escaping of the 's' (search) parameter within the administrative booking listing page. The vulnerability occurs when the search value is passed directly into a LIKE clause of a SQL query. An attacker with 'Hotel Manager' or 'Booking Editor' roles can exploit this by submitting crafted search queries to perform time-based blind SQL injection. This allows for the extraction of sensitive data from the WordPress database. The issue was fixed in version 2.3.2 by implementing proper escaping using esc_like() and prepared statements.
Affected products
- Unknown WP Hotel Booking < 2.3.2
Timeline
- 2026-06-29: disclosed: Initial discovery/disclosure date mentioned in references
- 2026-07-09: advisory: WPScan advisory published
- 2026-07-30: patched: NVD publication date and fix confirmed in version 2.3.2