Executive brief
The WP Hotel Booking plugin for WordPress, which manages room reservations and pricing, contains a security flaw in how it handles internal requests. This allows any registered user, such as a basic subscriber, to view sensitive information including other customers' booking details, active discount coupons, and internal pricing data. This could lead to the exposure of customer data and the unauthorized use of promotional codes.
Technical details
The WP Hotel Booking plugin fails to implement proper authorization checks (capability checks) within multiple AJAX handlers, specifically 'hotel_booking_load_order_item', 'hotel_booking_load_coupon_ajax', and 'hotel_booking_load_other_full_calendar'. While the plugin uses nonces for CSRF protection, these nonces are leaked globally via the 'hotel_settings' JavaScript object, making them accessible to any authenticated user. An attacker with Subscriber-level privileges can exploit this to perform Insecure Direct Object Reference (IDOR) attacks to view booking metadata, enumerate all active coupons by passing an empty string to the coupon handler, and disclose room pricing schedules. The vulnerability is addressed in version 2.3.1.
Affected products
- Unknown WP Hotel Booking < 2.3.1
Timeline
- 2026-05-29: disclosed: Initial public disclosure by WPScan
- 2026-05-29: advisory
- 2026-06-19: other: CVE published to NVD dataset