WP Hotel Booking Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the WP Hotel Booking plugin for WordPress, affecting all versions through 2.2.7. The issue arises because the plugin's 'hotel_booking_fetch_customer_info' AJAX action is accessible to unauthenticated users without adequate capability checks. It relies solely on a nonce for protection, enabling unauthorized attackers to retrieve sensitive customer data such as full names, addresses, phone numbers, and email addresses. Exploitation requires a valid email address and a publicly accessible nonce.

Impact

Exploitation of this vulnerability allows unauthenticated users to access sensitive customer information, including names, addresses, phone numbers, and email addresses.

Reproduction

To reproduce this vulnerability, send a request to the 'hotel_booking_fetch_customer_info' AJAX action without authentication. Include a valid email address and a publicly accessible nonce. The response will contain sensitive customer information associated with the provided email address.

Remediation

Users are advised to update the WP Hotel Booking plugin to version 2.2.8 or later, where this vulnerability has been patched.

Added: Jan 17, 2026, 3:21 AM
Updated: Jan 17, 2026, 3:21 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
8.9
remediation
7.7
relevance
2.1
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.