CVE-2023-0768
08.05.2023, 14:15
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.Enginsight
| Vendor | Product | Version |
|---|---|---|
| avirato | hotels_online_booking_engine | 𝑥 ≤ 5.0.5 |
𝑥
= Vulnerable software versions