WordPress Plugin Vulnerabilities

Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR

Description

The plugin does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Haitam Lazaar
Submitter
Haitam Lazaar
Verified
Yes

Timeline

Publicly Published
2026-08-06 (about 4 days ago)
Added
2026-08-06 (about 3 days ago)
Last Updated
2026-08-06 (about 3 days ago)

Other