Executive brief
The Byteflows Travel & Hotel Booking plugin for WordPress, which manages travel and accommodation reservations, contains a security flaw that allows unauthorized individuals to access sensitive system information. An attacker could exploit this to view data that should be restricted, potentially leading to further compromises of the website or its users. This issue affects all versions up to and including 1.0.0, and it is recommended to update to version 1.0.1 immediately.
Technical details
The Byteflows Travel & Hotel Booking plugin for WordPress (versions <= 1.0.0) is vulnerable to sensitive data exposure (CWE-497). The vulnerability allows an unauthenticated remote attacker to access sensitive system information due to improper restriction of access to internal data or configuration details. This exposure can be leveraged by attackers to gather intelligence for subsequent attacks. The issue is resolved in version 1.0.1. No virtual patches are available due to the specific nature of the vulnerability.
Affected products
- Byteflows Byteflows Travel & Hotel Booking <= 1.0.0
Timeline
- 2026-07-09: other: Reported by researcher Ananda Dhakal
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD
- 2026-07-27: patched: Version 1.0.1 released to address the vulnerability