Impact
The Jetmonsters Hotel Booking Lite plugin has a vulnerability that allows sensitive subscriber data to be exposed. Affected versions up to 6.0.3 may return personal and booking information to unauthenticated callers, violating confidentiality (CWE‑201). Attackers can obtain details such as names, contact information, and reservation history, potentially enabling phishing or identity‑theft attacks.
Affected Systems
The flaw exists in the WordPress Hotel Booking Lite plugin distributed by Jetmonsters, specifically versions 6.0.3 and earlier. Sites running these plugin versions are vulnerable to the data exposure.
Risk and Exploitability
The CVSS score of 6.5 signals medium severity risk, while the EPSS score of < 1% implies a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an unauthenticated request to a publicly accessible plugin endpoint that returns subscriber details could trigger the flaw, allowing attackers to harvest sensitive data without needing privileged access.
OpenCVE Enrichment