Impact
The Jetmonsters Hotel Booking Lite plugin has a flaw that leads to sensitive subscriber information being exposed in versions up to 6.0.3, allowing unauthorized individuals to access personal and booking details (CWE‑201).
Affected Systems
The vulnerability affects the Jetmonsters Hotel Booking Lite plugin, specifically versions 6.0.3 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity risk, while an EPSS score of < 1% suggests a low probability of exploitation and the vulnerability is not listed in CISA KEV. The attack vector is not explicitly documented, but because the flaw permits unauthenticated viewing of subscriber data, it is inferred that an attacker could issue a request to a publicly exposed plugin endpoint to retrieve the information.
OpenCVE Enrichment