Impact
The vulnerability is a missing authorization flaw that allows users to bypass the plugin’s intended access controls. This Broken Access Control can lead to unauthorized viewing or manipulation of bookings, schedules, and related data. The flaw is classified under CWE-862 and the CVSS score of 5.4 indicates moderate severity.
Affected Systems
The issue affects the WordPress plugin Online Booking & Scheduling Calendar for WordPress by vcita, versions up to and including 4.5.5. The plugin is distributed by vcita and is referenced by the identifier vcita:online_booking_scheduling_calendar. No earlier version is explicitly documented as safe.
Risk and Exploitability
With a CVSS base score of 5.4, the vulnerability represents moderate risk when combined with a low EPSS probability of less than 1%. It is not listed in the CISA KEV catalog, implying no known exploit in the wild. The likely attack vector is an authenticated user who can obtain elevated capabilities by exploiting incorrectly configured role limits; the flaw is not exploitable by unauthenticated users based on the provided description.
OpenCVE Enrichment