S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1952 Scanner

CVE-2022-1952 scanner - Unrestricted File Upload vulnerability in Free Booking Plugin for Hotels, Restaurant and Car Rental plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1952
9.8
CVSS

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC
AFFECTED< 1.1.16SAFE ✓≥ 1.1.16
Updated Aug 22, 2026View on NVD →
Detail

The Free Booking Plugin for Hotels, Restaurant and Car Rental is a WordPress plugin that allows businesses in the hospitality industry to facilitate bookings on their website. The plugin is designed to be user-friendly and customizable, offering features such as reservation management, booking forms, and payment integration. It is a popular choice for many websites in the industry who want to streamline their booking process and improve customer experience.

However, the plugin has been found to have a critical vulnerability, identified as CVE-2022-1952. This vulnerability is caused by insufficient input validation, which allows attackers to upload arbitrary files to a website. This can subsequently lead to remote code execution, allowing attackers to take control of the website and potentially steal sensitive information or distribute malware.

If exploited, this vulnerability can have serious consequences for businesses using the Free Booking Plugin for Hotels, Restaurant and Car Rental. Attackers can gain access to sensitive data, including customer information and payment details, which can lead to financial loss and reputational damage.  In addition, the attack can compromise the availability and integrity of the website, leading to a customer loss.

At s4e.io, we believe in providing comprehensive and effective security solutions for businesses of all sizes. Thanks to our pro features, those who read this article can easily and quickly learn about vulnerabilities in their digital assets and protect their business from potential cyber-attacks. We encourage website owners to take advantage of our platform and stay ahead of potential security risks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that website owners using this plugin take the following precautions:

  • Update to the latest version of the plugin which has resolved the vulnerability 
  • Disallow execution of PHP files in directories containing user-controlled files. 
  • Implement input validation for user upload fields 
  • Implement server-side validation of file extensions
  • Limit or remove file upload functionality, if it is not necessary

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-1952 scanner - Unrestricted File Upload vulnerability in Free Booking Plugin for Hotels, Restaurant and Car Rental plugin for WordPress | S4E