Impact
The Hotel Listing plugin suffers from a missing authorization flaw that allows attackers to interact with functionalities or data that should be restricted. This broken access control can lead to unauthorized viewing or modification of listings and other protected information, and it is classified as CWE‑862.
Affected Systems
The vulnerability affects the WordPress Hotel Listing plugin from e‑plugins, impacting all released versions up to and including 1.4.2. No newer fixed versions are specified in the data provided.
Risk and Exploitability
The CVSS score of 7.6 indicates significant impact, while the EPSS score of below 1% suggests low probability of exploit; the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is exposure of administrative endpoints within the plugin, which an attacker could reach from a web-based interface to bypass intended access restrictions. Precise exploitation conditions are not detailed, but any user with sufficient privileges to reach the plugin’s pages could potentially abuse the missing checks.
OpenCVE Enrichment