CVE-2026-57347
Deferred Deferred - Pending Action

Subscriber Sensitive Data Exposure in Hotel Booking Lite

Vulnerability report for CVE-2026-57347, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-02

Last updated on: 2026-07-02

Assigner: Patchstack

Description

Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-02
Last Modified
2026-07-02
Generated
2026-07-02
AI Q&A
2026-07-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
motopress hotel_booking_lite to 6.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WordPress Hotel Booking Lite Plugin, versions 6.0.3 and earlier, contains a vulnerability classified as Sensitive Data Exposure. This flaw allows attackers to access sensitive information that should normally be restricted.

The vulnerability has a moderate severity with a CVSS score of 6.5, indicating a significant risk and potential for exploitation in widespread attacks targeting many websites.

Immediate action is recommended, such as updating the plugin to version 6.0.4 or later, or applying mitigation measures provided by Patchstack.

Impact Analysis

This vulnerability can lead to unauthorized exposure of sensitive subscriber data from the Hotel Booking Lite plugin.

Attackers who exploit this flaw may gain access to confidential information, which could be used to further compromise the system or conduct additional attacks.

Such exposure can result in privacy breaches, loss of customer trust, and potential financial or reputational damage.

Mitigation Strategies

Immediate action is recommended to mitigate the vulnerability in the WordPress Hotel Booking Lite Plugin versions 6.0.3 and earlier.

  • Update the plugin to version 6.0.4 or later.
  • If updating is not possible, seek assistance from your hosting provider or web developer.
  • Use the mitigation rule provided by Patchstack to block attacks until the plugin is updated.
  • Consider using Patchstack's tools for automated vulnerability management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57347. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart