CVE-2025-66078: Jetmonsters Hotel Booking Lite
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3.
Affected products
- Jetmonsters Hotel Booking Lite: up to and including 5.2.3
Published 2025-12-18. Last modified 2026-06-17.