{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-23T16:18:53.220","vulnerabilities":[{"cve":{"id":"CVE-2025-14352","sourceIdentifier":"security@wordfence.com","published":"2026-01-07T12:16:54.453","lastModified":"2026-06-17T08:35:47.830","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification without capability checks. This makes it possible for unauthenticated attackers to modify arbitrary booking records by obtaining a nonce from the public booking form."},{"lang":"es","value":"El plugin Awesome Hotel Booking para WordPress es vulnerable a la modificación no autorizada de datos debido a una autorización incorrecta en el manejador del shortcode room-single.php en todas las versiones hasta la 1.0, inclusive. Esto se debe a que el plugin se basa únicamente en la verificación de nonce sin comprobaciones de capacidad. Esto hace posible que atacantes no autenticados modifiquen registros de reserva arbitrarios al obtener un nonce del formulario de reserva público."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"nahian91","product":"Awesome Hotel Booking","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-07T15:22:53.684976Z","id":"CVE-2025-14352","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3436372%40awesome-hotel-booking&new=3436372%40awesome-hotel-booking","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4fe0a08e-eee2-4d48-bb38-dd58bff79118?source=cve","source":"security@wordfence.com"}]}}]}