Impact
The vulnerability is a missing authorization check that allows an attacker to change the plugin’s settings without proper authentication. By exploiting this flaw, an attacker can alter booking options, email notifications, or other configuration parameters, potentially disrupting service or redirecting users to malicious destinations. The weakness is classified as CWE‑862, indicating an improper authorization control.
Affected Systems
The issue affects the WordPress VikBooking Hotel Booking Engine & PMS plugin, version 1.7.2 and earlier. Any WordPress installation that has a legacy or unpatched VikBooking instance is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is currently low, and the vulnerability is not listed in the CISA KEV catalog. Typically, exploitation would require an authenticated admin session or an attacker who can craft a CSRF attack against the plugin’s settings page. No additional local or remote prerequisites are noted in the provided data.
OpenCVE Enrichment
EUVD