Impact
The flaw is a Missing Authorization vulnerability that allows an attacker to invoke Booking and Rental Manager functions that are not protected by proper access control lists. The plugin, available as a WordPress extension, lets unauthorized users change or delete booking and rental data, potentially exposing sensitive information or disrupting service. This weakness is classified as CWE‑862 and carries a CVSS score of 6.5, indicating moderate severity.
Affected Systems
The vulnerability affects the WordPress Booking and Rental Manager plugin developed by magepeopleteam, specifically versions 2.3.8 and all earlier releases. Site owners running these versions on a WordPress installation are exposed unless the plugin is updated or removed.
Risk and Exploitability
The EPSS score is below 1 percent, indicating a low exploitation likelihood, and the flaw is not yet catalogued in CISA’s KEV list. Based on the description, it is inferred that the plugin’s administrative functions can be accessed over HTTP, which a remote attacker could reach by crafting requests to privileged endpoints without authentication. The potential impact is limited to the attacker’s privilege level; if the user is already operating with higher permissions, the attacker could modify or delete booking data.
OpenCVE Enrichment
EUVD