
CultBooking Hotel Booking Engine Security & Risk Analysis
wordpress.org/plugins/cultbooking-booking-engineCultBooking Engine for WordPress is a powerful and easy-to-use plugin that allows you to manage your bookings and channels from your WordPress site.
Is CultBooking Hotel Booking Engine Safe to Use in 2026?
Mostly Safe
Score 71/100CultBooking Hotel Booking Engine is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "cultbooking-booking-engine" v2.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, is also a strength. However, the plugin struggles with output escaping, with only 20% of outputs being properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is improperly handled. Furthermore, the lack of nonce checks on the identified entry point and the limited capability checks suggest potential weaknesses in authorization and session integrity.
The vulnerability history is a significant concern. The presence of a medium severity Cross-Site Request Forgery (CSRF) vulnerability that remains unpatched, and the plugin's history of CSRF vulnerabilities, indicates a recurring pattern of issues related to securing actions that modify state. While there are no critical or high severity vulnerabilities identified in the current static analysis, the unpatched CSRF issue coupled with the insufficient output escaping and authorization checks points to a medium to high risk profile for this version.
In conclusion, while the plugin demonstrates good practices in handling SQL and limiting its direct attack vectors, the significant lack of proper output escaping and the presence of an unpatched CSRF vulnerability are critical weaknesses. The pattern of CSRF vulnerabilities suggests a need for more robust security awareness and implementation within the development process.
Key Concerns
- Unpatched medium severity CVE (CSRF)
- Insufficient output escaping (20% properly escaped)
- No nonce checks on entry points
- Limited capability checks
CultBooking Hotel Booking Engine Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CultBooking Hotel Booking Engine <= 2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CultBooking Hotel Booking Engine Code Analysis
Output Escaping
Data Flow Analysis
CultBooking Hotel Booking Engine Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
CultBooking Hotel Booking Engine Maintenance & Trust
Maintenance Signals
Community Trust
CultBooking Hotel Booking Engine Alternatives
MotoPress Hotel Booking
motopress-hotel-booking-lite
The #1 Hotel Booking and Vacation Rental Plugin for WordPress. Online payments, seasons, rates, free or paid extras, coupons, taxes & fees.
VikBooking Hotel Booking Engine & PMS
vikbooking
Famous Booking Engine, PMS and Hotel Reservations plugin for property managers. The best solution for accommodations to drive more direct bookings.
Sirvoy Booking Engine
sirvoy-booking-engine
Sirvoy booking engine - Non-Commission Direct Bookings from Your Website. Sirvoy can also help you to receive bookings from channels, and much more.
Jomres Hotel Booking Engine for WordPress
jomres
Build your own Online Travel Agency like Booking.com or AirBNB
1Day Booking Engine
1day-io
Simple, modern and flexible booking engine for your hotel. Let customers book rooms easily without being redirected away from your website.
CultBooking Hotel Booking Engine Developer Profile
1 plugin · 100 total installs
How We Detect CultBooking Hotel Booking Engine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cultbooking-booking-engine/assets/css/chbecm-style.css/wp-content/plugins/cultbooking-booking-engine/assets/js/iframe.js/wp-content/plugins/cultbooking-booking-engine/assets/js/chbecm-init.js/wp-content/plugins/cultbooking-booking-engine/assets/js/iframe.js/wp-content/plugins/cultbooking-booking-engine/assets/js/chbecm-init.jsHTML / DOM Fingerprints
chbecm-booking-enginedata-chbecm-hotel-id<iframe class="chbecm-booking-engine"