The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0. This is due to the plugin relying solely on nonce verification without capability checks. This makes it possible for unauthenticated attackers to modify arbitrary booking records by obtaining a nonce from the public booking form.
References
Configurations
No configuration.
History
07 Jan 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-07 12:16
Updated : 2026-01-08 18:08
NVD link : CVE-2025-14352
Mitre link : CVE-2025-14352
CVE.ORG link : CVE-2025-14352
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
