CVE-2025-14075

T

he WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protection. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including full names, addresses, phone numbers, and email addresses by providing a valid email address and a publicly accessible nonce.

Configurations

No configuration.

History

17 Jan 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-17 03:16

Updated : 2026-01-26 15:05


NVD link : CVE-2025-14075

Mitre link : CVE-2025-14075

CVE.ORG link : CVE-2025-14075


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor