Impact
This vulnerability is a missing authorization flaw that enables attackers to bypass the plugin’s configured security levels and potentially perform unauthorized actions within the WordPress site. The weakness is identified as CWE‑862 and could allow an attacker to elevate privileges or access restricted functionality, compromising data integrity and confidentiality for the affected site.
Affected Systems
WordPress plugin WeDesignTech Ultimate Booking Addon from BuddhaThemes is affected for all versions up to and including 1.0.3.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s web interface, although specific exploitation details are not provided in the advisory. Existing access controls must be verified and upgraded to mitigate this risk.
OpenCVE Enrichment