Impact
The WP Booking System plugin version 2.0.19.12 and earlier allow an attacker to retrieve sensitive data embedded in responses sent by the plugin. This is an insertion of sensitive information into transmitted data, leading to data exposure. The weakness is identified as CWE‑201, which involves improper handling of confidential information in output.
Affected Systems
Roland Murg WP Booking System 2.0.19.12 and earlier are affected. The vulnerability is present in all releases from the first available version through 2.0.19.12 inclusive.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate risk level, and the EPSS score of less than 1% suggests that exploitation of this vulnerability is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can cause the plugin to expose confidential data by accessing plugin endpoints or views that are publicly or unauthenticatedly available.
OpenCVE Enrichment