CyberRota Analysis
AI-GeneratedThe WP Hotel Booking plugin for WordPress prior to version 2.3.2 is vulnerable to SQL injection due to improper sanitization and escaping of a search parameter in administrative listings. This flaw allows users with booking-management roles to execute malicious SQL queries, potentially compromising the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.