Impact
The flaw is a CSRF vulnerability that allows an attacker to trigger actions within the Booqable Rental plugin by tricking an authenticated user into sending a forged request. These actions could include modifying or canceling reservations, or otherwise changing data that belongs to the target user. The weakness is a Cross‑Site Request Forgery (CWE‑352) flaw that bypasses the plugin’s expected confirmation flow.
Affected Systems
The vulnerability is present in the WordPress Booqable Rental plugin, versions up to and including 2.4.25, distributed by Booqable Rental Software. No other vendors or product lines are affected.
Risk and Exploitability
The CVSS score of 4.3 classifies this issue as moderate severity, and the EPSS score of less than 1 % indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to convince a logged‑in user to visit a crafted URL or submit a malicious form that triggers the vulnerable action. The likely attack vector is a malicious link or form that exploits the CSRF flaw. Based on the description, it is inferred that the flaw operates without additional authentication beyond the user’s existing session, making the exploit low barrier once credentials are available.
OpenCVE Enrichment
EUVD