Impact
A flaw in the FluentBooking Pro plugin for WordPress allows an unauthenticated attacker to bypass access controls and perform privileged operations, potentially reading or modifying booking data and other sensitive information. The weakness is categorized as CWE‑862 and results in the ability to act with elevated privileges without needing to authenticate, which can compromise confidentiality and integrity of booking data and site operations.
Affected Systems
Any WordPress site that has the FluentBooking Pro plugin installed in a version earlier than 2.5.0 is affected. The vulnerability affects all instances of the plugin regardless of whether the plugin is enabled for public or admin usage and applies to all sites running the specified vendor and product.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity vulnerability that is exploitable from the network by any visitor, as authentication is not required. No EPSS score is available, and the issue is not listed in CISA KEV; however, the lack of authentication checks makes exploitation straightforward. An attacker can craft requests to the plugin’s endpoints and gain unauthorized access to booking data and administrative actions.
OpenCVE Enrichment