CVE-2025-14075Sensitive Information Exposure in WP Hotel Booking

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 81.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 17

Description

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for protection. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including full names, addresses, phone numbers, and email addresses by providing a

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-p429-p65m-q8hj: The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 22026-01-17
CVEList
WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter2026-01-17

🕵️Threat Intelligence

1
Wiz
CVE-2025-14075 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-14075 — Sensitive Information Exposure | cvebase