CVE-2025-68006: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68006 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) affecting the Deetronix Booking Ultra Pro WordPress plugin. It allows authenticated attackers with at least Subscriber-level privileges to retrieve embedded sensitive data that should not be accessible to regular users. All versions up to and including 1.1.23 are affected, and as of the time of reporting, no official patch has been released. The vulnerability was reported by researcher Denver Jackson on September 11, 2025, and published by Patchstack on December 26, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses sent to authenticated users who should not have access to it. The attack vector is network-based with low attack complexity, requiring only low-level authenticated access (Subscriber role) and no user interaction. The specific mechanism by which sensitive data is embedded in plugin responses has not been fully detailed in public disclosures, but the vulnerability is consistent with patterns where API responses or AJAX handlers return more data than intended for the requesting user's privilege level (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges (Subscriber level) to access sensitive information that is normally restricted to higher-privileged users or administrators. This could expose booking data, customer personal information, or configuration details managed by the plugin, which could then be leveraged to facilitate further attacks against the WordPress site or its users. There is no integrity or availability impact; the risk is confined to confidentiality (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified for this vulnerability. The EPSS score is approximately 0.018% (0.000180), indicating a low probability of exploitation in the near term. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that medium-severity vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Booking Ultra Pro plugin (version ≤ 1.1.23) using tools like WPScan or by checking publicly accessible plugin metadata (e.g., /wp-content/plugins/booking-ultra-pro/readme.txt).
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site, which is often open to public registration.
  3. Trigger sensitive data exposure: As an authenticated Subscriber, send crafted requests (e.g., AJAX calls or REST API requests) to plugin endpoints that return data intended for higher-privileged users.
  4. Retrieve sensitive data: Parse the plugin's response to extract embedded sensitive information such as booking records, customer details, or administrative configuration data.
  5. Leverage extracted data: Use the retrieved information for further attacks, such as targeted phishing, credential stuffing, or identifying additional vulnerabilities in the system (Patchstack).

Indicators of compromise

  • Network: Unusual or repeated authenticated requests to Booking Ultra Pro plugin endpoints (e.g., WordPress AJAX handlers or REST API routes associated with booking-ultra-pro) from low-privilege user accounts.
  • Logs: WordPress access logs showing Subscriber-level users making frequent requests to plugin-specific endpoints that typically serve administrative data; anomalous patterns of data retrieval from a single authenticated session.
  • File System: No file system artifacts are expected for this type of read-only data exposure vulnerability.

Mitigation and workarounds

As of the time of disclosure, no official patch from the developer (Deetronix) is available for versions up to and including 1.1.23. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider deactivating and removing the plugin until a patched version is available, restricting public user registration if not required, or deploying a web application firewall (WAF) solution such as Patchstack to mitigate the risk (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management