Impact
The Easy Booking WordPress plugin, versions prior to 3.5.0, lacks server‑side enforcement of a product’s minimum booking duration. An unauthenticated attacker can craft requests that add a booking with a duration shorter than permitted or use a cart calculation that underprices the order. This flaw allows malicious or accidental placement of orders that do not meet the configured minimum requirements, potentially leading to financial loss and violation of business rules.
Affected Systems
All installations of the Easy Booking plugin running any version earlier than 3.5.0 are affected. Administrators should review their current plugin version and ensure upgrades apply to all sites where the plugin is active.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation yet. The attack vector is inferred to be remote, as the flaw can be triggered by any unauthenticated user interacting with the booking interface, typically through a crafted HTTP request or automated script. An attacker does not need administrative privileges, but can place multiple low‑value or revenue‑losing orders that bypass business‑rule enforcement.
OpenCVE Enrichment