Impact
The flaw is a missing authorization check that lets an attacker view or modify booking information in the wpdevart Booking calendar, Appointment Booking System plugin. This can let an unauthenticated or low‑privilege user gain access to sensitive data or alter scheduling details, compromising confidentiality and integrity of the booking system.
Affected Systems
Affects the Booking calendar, Appointment Booking System plugin from its first release up to and including version 3.2.30. Systems running any of those versions on WordPress are subject to the issue.
Risk and Exploitability
The CVSS score of 5.3 classifies it as a medium severity vulnerability. Its EPSS score is below 1 %, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It can be exploited by exploiting misconfigured access control levels; an attacker only needs to have an account with insufficient privileges or manipulate the access control logic to gain unauthorized rights.
OpenCVE Enrichment