
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14075 is a Sensitive Information Exposure vulnerability in the WP Hotel Booking plugin for WordPress, developed by ThimPress. All versions up to and including 2.2.7 are affected. The flaw allows unauthenticated attackers to retrieve sensitive customer data — including full names, addresses, phone numbers, and email addresses — by exploiting an improperly protected AJAX action. It was disclosed on January 16–17, 2026, with Wordfence as the reporting CNA. The CVSS v3.1 base score is 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The plugin registers the hotel_booking_fetch_customer_info AJAX action and makes it accessible to unauthenticated users (wp_ajax_nopriv_) without implementing proper WordPress capability checks. Protection relies solely on a nonce, which is publicly accessible on the site's frontend, making it trivially obtainable by any visitor. An attacker can then supply a known or guessed customer email address along with the retrieved nonce to invoke the AJAX endpoint and receive the corresponding customer record (Wordfence, WordPress Trac).
Successful exploitation allows any unauthenticated attacker to enumerate and harvest hotel booking customer records, exposing personally identifiable information (PII) including full names, physical addresses, phone numbers, and email addresses. This data exposure creates privacy risks for hotel guests and may result in regulatory consequences (e.g., GDPR violations) for site operators. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.041%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity — requiring no authentication, no privileges, and no user interaction — makes it straightforward to exploit once a valid customer email and the publicly accessible nonce are obtained (Wordfence, Red Hat CVE).
/wp-admin/admin-ajax.php) with the action parameter set to hotel_booking_fetch_customer_info, the retrieved nonce, and the target customer email address./wp-admin/admin-ajax.php with action=hotel_booking_fetch_customer_info from a single or rotating IP address, especially with varying email parameters.admin-ajax.php with the above action parameter from unauthenticated sessions; unusual off-hours access patterns targeting this endpoint.Update the WP Hotel Booking plugin to version 2.2.8 or later, which addresses the missing capability check on the hotel_booking_fetch_customer_info AJAX action. The patch can be reviewed in the WordPress plugin repository changeset. If immediate patching is not possible, consider temporarily disabling the plugin or restricting access to wp-admin/admin-ajax.php for unauthenticated users via WAF rules, though this may impact legitimate plugin functionality (Wordfence, WordPress Trac).
Wordfence disclosed the vulnerability and assigned the CVE as the reporting CNA. The vulnerability received standard coverage from security aggregators including VulDB, Vulners, and CIRCL, as well as a brief technical write-up from Infinit Security. No notable researcher commentary or significant social media discussion has been identified beyond routine CVE tracking (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."