PT-2025-50924 · WordPress · The Simple Bike Rental

Athiwat Tiprasaharn

·

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-14065

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Simple Bike Rental plugin for WordPress versions up to and including 1.0.6
Description The plugin is susceptible to unauthorized data access because of a missing capability check on the simpbire carica prenotazioni AJAX action. Authenticated attackers with Subscriber-level access or higher can retrieve all booking records, which contain personally identifiable information (PII) such as names, email addresses, and phone numbers. The affected API endpoint is simpbire carica prenotazioni.
Recommendations Update The Simple Bike Rental plugin to a version later than 1.0.6.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14065

Affected Products

The Simple Bike Rental