thimpress wp hotel booking

Published Atomicorp research notes for CVEs affecting thimpress wp hotel booking where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2020-29047WP Hotel Booking < 1.10.4 - PHP Object Injection9.8 (v3.1)Critical330889
CVE-2023-5652WP Hotel Booking <= 2.0.7 - SQL Injection9.8 (v3.1)Critical340156 , 380122
CVE-2024-3605WP Hotel Booking <= 2.1.0 - SQL Injection9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2026-15094WP Hotel Booking <= 2.3.2 - Cross-Site Scripting6.1 (v3.1)Medium300002