peter bassill · operator
$ cve CVE-2023-5991 JSON

CVE-2023-5991

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.31% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2023-12-26
Last modified2026-06-17

Affected (1)

VendorProduct
motopresshotel booking lite

References

→ the Explorer  ·  watch your stack  ·  NVD