
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68006 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) affecting the Deetronix Booking Ultra Pro WordPress plugin. It allows authenticated attackers with at least Subscriber-level privileges to retrieve embedded sensitive data that should not be accessible to regular users. All versions up to and including 1.1.23 are affected, and as of the time of reporting, no official patch has been released. The vulnerability was reported by researcher Denver Jackson on September 11, 2025, and published by Patchstack on December 26, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses sent to authenticated users who should not have access to it. The attack vector is network-based with low attack complexity, requiring only low-level authenticated access (Subscriber role) and no user interaction. The specific mechanism by which sensitive data is embedded in plugin responses has not been fully detailed in public disclosures, but the vulnerability is consistent with patterns where API responses or AJAX handlers return more data than intended for the requesting user's privilege level (Patchstack).
Successful exploitation allows an authenticated attacker with minimal privileges (Subscriber level) to access sensitive information that is normally restricted to higher-privileged users or administrators. This could expose booking data, customer personal information, or configuration details managed by the plugin, which could then be leveraged to facilitate further attacks against the WordPress site or its users. There is no integrity or availability impact; the risk is confined to confidentiality (Patchstack).
No public proof-of-concept exploit code has been identified for this vulnerability. The EPSS score is approximately 0.018% (0.000180), indicating a low probability of exploitation in the near term. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that medium-severity vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
/wp-content/plugins/booking-ultra-pro/readme.txt).booking-ultra-pro) from low-privilege user accounts.As of the time of disclosure, no official patch from the developer (Deetronix) is available for versions up to and including 1.1.23. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider deactivating and removing the plugin until a patched version is available, restricting public user registration if not required, or deploying a web application firewall (WAF) solution such as Patchstack to mitigate the risk (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."