Impact
The bug is a missing authorization check in the QuanticaLabs Car Park Booking System for WordPress plugin. Because the plugin fails to enforce proper access control on some endpoints, an attacker could potentially execute unauthorized operations, leading to unintended disclosure or alteration of booking information. The impact could compromise confidentiality and integrity of booking data.
Affected Systems
The QuanticaLabs Car Park Booking System for WordPress plugin for all released versions up to and including version 2.6 is affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw represents an authorization bypass, the likely attack vector is remote via crafted HTTP requests to the WordPress site that hosts the plugin. This inference assumes the attacker has network access to the site, but no user credentials are required. No unique system or configuration prerequisites are specified in the CVE data.
OpenCVE Enrichment
EUVD