Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass configured access controls within the Fluent Booking plugin for WordPress. By exploiting this flaw, an attacker could elevate privileges and perform actions reserved for higher‑level users, potentially accessing or modifying booking data. The weakness maps to CWE‑862: Missing Authorization.
Affected Systems
The flaw affects the Shahjahan Jewel Fluent Booking plugin for WordPress, specifically all releases at or below version 1.9.11. No specific OS or platform is mentioned, so any WordPress installation using these plugin versions is susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at this time. It is not listed in CISA KEV. Because the flaw relies on incorrect access configurations, the likely attack path is a web‑based exploitation through the plugin’s administrative interface, potentially requiring an authenticated session with at least some user privileges. Without such credentials, exploitation would be difficult.
OpenCVE Enrichment