Impact
Missing authorization in the Course Booking System plugin allows users to access functionality that is not properly constrained by access control lists. The flaw could enable an attacker to retrieve or manipulate booking data or perform privileged actions that should otherwise be restricted.
Affected Systems
The vulnerability affects the ComMotion Course Booking System WordPress plugin up to and including version 6.1. All installed instances of this plugin in that version range are potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 and a very low EPSS (<1%) indicate moderate severity and a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. An attacker can likely exploit the flaw by accessing plugin endpoints without proper permission checks, potentially using any authenticated WordPress role or even unauthenticated users depending on the site’s configuration. The attack vector is remote and does not require privileged system access beyond use of the web application.
OpenCVE Enrichment
EUVD