PatchSiren cyber security CVE debrief
CVE-2025-68014 awethemes CVE debrief
CVE-2025-68014 AweBooking Sensitive Data Exposure Vulnerability. The AweBooking plugin for WordPress has a sensitive data exposure vulnerability, allowing retrieval of embedded sensitive data. This issue affects AweBooking versions from n/a through <= 3.2.26. WordPress site administrators and security teams should assess their exposure and verify plugin versions to prevent potential sensitive data exposure. The vulnerability has a CVSS score of 6.5 and a MEDIUM severity level. The CVE record was published on 2026-01-05T11:17:41.387Z.
- Vendor
- awethemes
- Product
- AweBooking
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-05
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-05
- Advisory updated
- 2026-09-30
Who should care
WordPress site administrators and security teams using the AweBooking plugin should assess their exposure and verify plugin versions to prevent potential sensitive data exposure. They should also monitor WordPress site logs for potential sensitive data exposure and review AweBooking plugin configurations to prevent unauthorized data access. Additionally, they should review and update AweBooking plugin versions to the
Why it matters
CVE-2025-68014 AweBooking Sensitive Data Exposure Vulnerability requires verification of plugin versions and configurations to prevent potential sensitive data exposure. WordPress site administrators and security teams should assess their exposure and take necessary actions.
- Potential sensitive data exposure through AweBooking plugin
- Verification of plugin versions and configurations required
- Monitoring of WordPress site logs recommended
Technical summary
The AweBooking plugin for WordPress has a sensitive data exposure vulnerability, allowing retrieval of embedded sensitive data. The issue affects AweBooking versions from n/a through <= 3.2.26. This vulnerability has a CVSS score of 6.5 and a MEDIUM severity level. The vulnerability is caused by the plugin's inability to properly secure sensitive data, allowing attackers to retrieve it. WordPress site administrators and security teams should assess their exposure and verify plugin versions to prevent potential sensitive data exposure.
Defensive priority
Medium priority for WordPress site administrators and security teams
Recommended defensive actions
- Review and update AweBooking plugin versions to ensure the latest security patches are applied
- Monitor WordPress site logs for potential sensitive data exposure
- Verify AweBooking plugin configurations to prevent unauthorized data access
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the full scope of affected versions and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-68014 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-68014
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-68014 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-68014
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.