Executive brief
Hotel Booking Lite, a WordPress plugin used for managing property reservations, contains a security flaw that allows users with basic 'Subscriber' accounts to access sensitive information they should not be able to see. This could lead to the exposure of private customer or booking data, potentially compromising user privacy and business operations. Organizations using this plugin should update to the latest version to prevent unauthorized data access.
Technical details
A sensitive data exposure vulnerability (CWE-201) exists in the MotoPress Hotel Booking Lite plugin for WordPress. The flaw is present in versions up to and including 6.0.3. An authenticated attacker with Subscriber-level permissions can exploit this vulnerability to retrieve sensitive information that is not intended for their privilege level. The vulnerability stems from improper data handling or insufficient access controls within the plugin's components. A patch is available in version 6.0.4, which addresses the exposure by implementing proper authorization checks.
Affected products
- MotoPress (Jetmonsters) Hotel Booking Lite <= 6.0.3
Timeline
- 2026-05-18: disclosed: Reported by Sakimi to Patchstack
- 2026-07-01: patched: Version 6.0.4 released
- 2026-07-02: advisory: NVD publication date