CVE-2020-29047 is a critical PHP object injection vulnerability affecting the wp-hotel-booking plugin (versions through 1.10.2) for WordPress, stemming from an insecure unserialize operation on the thimpress_hotel_booking_1 cookie. With a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to execute arbitrary code, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit intelligence indicates public Nuclei templates exist, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10.2CPE matchmatch criteria | cpe:2.3:a:thimpress:wp_hotel_booking:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.