Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels in the GetBookingsWP WordPress plugin. Because the plugin fails to enforce proper permissions, a malicious actor can retrieve or modify booking data that should be protected, potentially compromising the confidentiality and integrity of sensitive user information. The weakness is classified as CWE‑862 (Missing Authorization).
Affected Systems
The issue affects the WordPress GetBookingsWP plugin from versions n/a through 1.1.27. It is distributed by istmoplugins and is commonly used on WordPress sites that handle booking information. Sites running any of these versions are susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw through the plugin’s exposed endpoints, possibly requiring only unauthenticated or minimally privileged access. The impact would be unauthorized data disclosure or modification of booking records, but no exploit is reported to cause service disruption.
OpenCVE Enrichment
EUVD