CVE-2025-14352

The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification without capability checks. This makes it possible for unauthenticated attackers to modify arbitrary booking records by obtaining a nonce from the public booking form.
Configurations

No configuration.

History

08 Apr 2026, 18:24

Type Values Removed Values Added
Summary
  • (es) El plugin Awesome Hotel Booking para WordPress es vulnerable a la modificación no autorizada de datos debido a una autorización incorrecta en el manejador del shortcode room-single.php en todas las versiones hasta la 1.0, inclusive. Esto se debe a que el plugin se basa únicamente en la verificación de nonce sin comprobaciones de capacidad. Esto hace posible que atacantes no autenticados modifiquen registros de reserva arbitrarios al obtener un nonce del formulario de reserva público.
Summary (en) The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0. This is due to the plugin relying solely on nonce verification without capability checks. This makes it possible for unauthenticated attackers to modify arbitrary booking records by obtaining a nonce from the public booking form. (en) The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification without capability checks. This makes it possible for unauthenticated attackers to modify arbitrary booking records by obtaining a nonce from the public booking form.
References
  • {'url': 'https://plugins.trac.wordpress.org/browser/awesome-hotel-booking/tags/1.0/admin/admin-shortcodes/inc/room-single.php#L67', 'source': 'security@wordfence.com'}
  • {'url': 'https://plugins.trac.wordpress.org/browser/awesome-hotel-booking/trunk/admin/admin-shortcodes/inc/room-single.php#L67', 'source': 'security@wordfence.com'}
  • () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3436372%40awesome-hotel-booking&new=3436372%40awesome-hotel-booking -

07 Jan 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-07 12:16

Updated : 2026-04-15 00:35


NVD link : CVE-2025-14352

Mitre link : CVE-2025-14352

CVE.ORG link : CVE-2025-14352


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization