CVE-2025-14075: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14075 is a Sensitive Information Exposure vulnerability in the WP Hotel Booking plugin for WordPress, developed by ThimPress. All versions up to and including 2.2.7 are affected. The flaw allows unauthenticated attackers to retrieve sensitive customer data — including full names, addresses, phone numbers, and email addresses — by exploiting an improperly protected AJAX action. It was disclosed on January 16–17, 2026, with Wordfence as the reporting CNA. The CVSS v3.1 base score is 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The plugin registers the hotel_booking_fetch_customer_info AJAX action and makes it accessible to unauthenticated users (wp_ajax_nopriv_) without implementing proper WordPress capability checks. Protection relies solely on a nonce, which is publicly accessible on the site's frontend, making it trivially obtainable by any visitor. An attacker can then supply a known or guessed customer email address along with the retrieved nonce to invoke the AJAX endpoint and receive the corresponding customer record (Wordfence, WordPress Trac).

Impact

Successful exploitation allows any unauthenticated attacker to enumerate and harvest hotel booking customer records, exposing personally identifiable information (PII) including full names, physical addresses, phone numbers, and email addresses. This data exposure creates privacy risks for hotel guests and may result in regulatory consequences (e.g., GDPR violations) for site operators. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.041%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity — requiring no authentication, no privileges, and no user interaction — makes it straightforward to exploit once a valid customer email and the publicly accessible nonce are obtained (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Hotel Booking plugin (version ≤ 2.2.7) using tools like WPScan, Shodan, or by inspecting plugin directories on target sites.
  2. Obtain the nonce: Load any page on the target WordPress site that includes the WP Hotel Booking frontend (e.g., a booking page). Inspect the page source or JavaScript variables to extract the publicly exposed nonce value used by the plugin.
  3. Identify a target email: Obtain a customer email address through open-source intelligence (OSINT), prior data leaks, or by attempting common/known email patterns associated with the hotel.
  4. Craft the AJAX request: Send an HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter set to hotel_booking_fetch_customer_info, the retrieved nonce, and the target customer email address.
  5. Retrieve customer data: Parse the JSON response, which returns the customer's full name, address, phone number, and email address for the provided email (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Repeated or automated HTTP POST requests to /wp-admin/admin-ajax.php with action=hotel_booking_fetch_customer_info from a single or rotating IP address, especially with varying email parameters.
  • Logs: WordPress access logs showing high-frequency requests to admin-ajax.php with the above action parameter from unauthenticated sessions; unusual off-hours access patterns targeting this endpoint.
  • Application: Responses returning customer PII in JSON format to unauthenticated requestors in server-side application logs (if verbose logging is enabled).

Mitigation and workarounds

Update the WP Hotel Booking plugin to version 2.2.8 or later, which addresses the missing capability check on the hotel_booking_fetch_customer_info AJAX action. The patch can be reviewed in the WordPress plugin repository changeset. If immediate patching is not possible, consider temporarily disabling the plugin or restricting access to wp-admin/admin-ajax.php for unauthenticated users via WAF rules, though this may impact legitimate plugin functionality (Wordfence, WordPress Trac).

Community reactions

Wordfence disclosed the vulnerability and assigned the CVE as the reporting CNA. The vulnerability received standard coverage from security aggregators including VulDB, Vulners, and CIRCL, as well as a brief technical write-up from Infinit Security. No notable researcher commentary or significant social media discussion has been identified beyond routine CVE tracking (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management