Impact
The vulnerability is a broken access control flaw that allows an attacker to bypass the plugin’s authorization checks and perform booking‑management operations without proper permissions. An attacker could create, modify, or cancel reservations, thereby compromising the availability and integrity of the booking system and potentially exposing sensitive customer data.
Affected Systems
The issue affects the WordPress Booking and Rental Manager plugin from magepeopleteam, versions up to and including 2.2.8. No other vendors or products were identified as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface from a remote location, as inferred from the description, by crafting requests to privileged endpoints that lack proper authorization checks.
OpenCVE Enrichment
EUVD