Executive brief
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to a sensitive data exposure flaw. This plugin is used by websites to manage bus ticket sales and seat assignments. An exploit could allow an unauthorized individual to view internal system information or embedded data that should be restricted, potentially aiding in further attacks against the site.
Technical details
The Bus Ticket Booking with Seat Reservation plugin for WordPress (versions prior to 5.6.5) contains an 'Exposure of Sensitive System Information to an Unauthorized Control Sphere' vulnerability (CWE-497). The flaw allows for the retrieval of embedded sensitive data that is normally restricted from standard users. According to the CVSS vector, the attack can be carried out over the network with low complexity, though it may require low-level authenticated privileges. An attacker can leverage this information to gain insights into the system's internal configuration or data structures. The issue is resolved in version 5.6.5.
Affected products
- magepeopleteam Bus Ticket Booking with Seat Reservation up to 5.6.5
Timeline
- 2026-02-20: disclosed: Vulnerability reported by Trương Hữu Phúc
- 2026-03-22: advisory: Patchstack published advisory
- 2026-04-08: advisory: NVD published CVE-2026-39572
- 2026-05-06: patched: Fixed in version 5.6.5