Description
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
Published: 2026-07-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthenticated users to access sensitive information stored by the Byteflows Travel & Hotel Booking plugin. According to the official description, this flaw is an instance of CWE‑497, which denotes unauthorized disclosure of data. Because no authentication is required, an attacker can read confidential data directly from the website, resulting in a confidentiality breach that could compromise user privacy and business secrets.

Affected Systems

Affected systems include the WordPress Byteflows Travel & Hotel Booking plugin, developed by Byteflows. Versions up to 1.0.0 are vulnerable. A patch is available in version 1.0.1 and later, which resolves the issue.

Risk and Exploitability

The CVSS score of 7.5 signals a high severity; the EPSS score is < 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been observed being actively exploited. The attack vector is unauthenticated, meaning any visitor with access to the affected site could trigger the data disclosure, provided the plugin exposes the relevant endpoints. Because the flaw does not require user credentials or elevated privileges, the risk of exploitation is relatively high in a public-facing environment. The combination of these factors warrants prompt remediation.

Generated by OpenCVE AI on August 3, 2026 at 17:35 UTC.

Remediation

Vendor Solution

Update the WordPress Byteflows Travel &amp; Hotel Booking Plugin to the latest available version (at least 1.0.1).


OpenCVE Recommended Actions

  • Apply the vendor’s patch by updating the Byteflows Travel & Hotel Booking Plugin to version 1.0.1 or newer.
  • If an update cannot be deployed immediately, restrict access to the plugin’s administrative pages by applying web‑application firewall rules or network segmentation, and monitor for suspicious activity.
  • Disable or restrict unauthenticated access to booking data endpoints via plugin settings or URL rewriting until a patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Byteflows
Byteflows byteflows Travel &amp; Hotel Booking
Wordpress
Wordpress wordpress
Vendors & Products Byteflows
Byteflows byteflows Travel &amp; Hotel Booking
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
Title WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Byteflows Byteflows Travel &amp; Hotel Booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:57:50.345Z

Reserved: 2026-07-05T21:27:56.024Z

Link: CVE-2026-59548

cve-icon Vulnrichment

Updated: 2026-07-27T14:57:44.112Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:04.837

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere