Impact
The vulnerability is a missing authorization flaw in the Awesome Event Booking plugin for WordPress, allowing an attacker to leverage incorrectly configured access control levels. This flaw may let an unauthenticated or low‑privilege user access or manipulate booking data, administrative functions, or sensitive configuration settings, ultimately enabling unauthorized modification or disclosure of information. The weakness is identified as CWE‑862.
Affected Systems
The affected product is AwesomeTOGI’s Awesome Event Booking WordPress plugin, versions up to and including 2.7.2. Any WordPress installation that has this plugin installed in those versions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require interaction with the plugin’s administrative endpoints, possibly through a simple web request, and would benefit from an authenticated session with a low‑privilege role. Mitigation is most effectively achieved by applying the vendor’s patch, as no widespread public exploits have been reported.
OpenCVE Enrichment
EUVD