Impact
A missing authorization flaw in the Syntactics, Inc. eaSYNC booking plugin allows an attacker to perform actions normally restricted to privileged users. This weakness can lead to unauthorized viewing or manipulation of booking data and configuration settings, exposing sensitive information and potentially enabling further attacks.
Affected Systems
The vulnerability applies to the WordPress eaSYNC booking plugin for all versions up to and including 1.3.19. Users running any of those releases are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the general population. The issue is not listed in the CISA KEV catalog. Based on the description, the most probable attack vector is via web requests to the plugin’s exposed endpoints, which an unauthenticated or low‑privilege user could exploit if anonymity is sufficient to reach those URLs.
OpenCVE Enrichment
EUVD