WP Hotel Booking, CVE-2025-14075
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jan 17, 2026
- Research Description
- The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protection. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including full names, addresses, phone numbers, and email addresses by providing a valid email address and a publicly accessible nonce.
- Affected versions
-
max 2.2.8.
- Status
-
vulnerable