CVEPublished 2023-11-201 article on news7 live referencesNVD data

CVE-2023-5652

Vulnerability data via CVEDB (Shodan)

CVSS v3.1
9.8
CRITICAL
EPSS percentile
99
Exploit Prediction Scoring System · top 1% of all CVEs
Description

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

Timeline
Published 2023-11-20

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (3)