CVE-2023-0768: Avirato Hotels Online Booking Engine
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
Affected products
- Avirato Hotels Online Booking Engine: up to and including 5.0.5
Published 2023-05-08. Last modified 2026-06-17.