← WordPress Vulnerabilities
WordPress security by component

Byteflows Travel & Hotel Booking

Byteflows Travel & Hotel Booking is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: byteflows-travel-hotel-booking

CVE-2026-59548: Byteflows Travel exposes protected data without authentication

Byteflows Travel & Hotel Booking through 1.0.0 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.

PublishedJul 27, 2026
Known safe version1.0.1
Safe version
Jul 27, 2026 CVE-2026-59548
Byteflows Travel exposes protected data without authentication
Byteflows Travel & Hotel Booking through 1.0.0 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
1.0.1
CVE7.5
NVDPending