Impact
The vulnerability is a missing authorization defect that allows attackers to exploit incorrectly configured access control security levels in the BA Book Everything plugin, enabling users who should not have permission to perform restricted actions and potentially manipulate booking data. The underlying weakness corresponds to CWE‑862, a classic broken access control issue.
Affected Systems
The plugin is affected in all WordPress installations running BA Book Everything version 1.8.16 or earlier. Any site that has the plugin installed without upgrading past this version is at risk. The issue is noted from "n/a" through the stated upper bound, meaning all previous releases lack the fix.
Risk and Exploitability
The CVSS score of 4.3 marks this flaw as having medium severity, reflecting a moderate impact and limited availability. The EPSS score of less than 1 percent indicates that, although the vulnerability is present, the current likelihood of exploitation in the wild is very low. It is not yet listed in the CISA KEV catalog. The plugin functions through the WordPress web interface, so the inferred attack vector is remote, via authenticated or unauthenticated web requests, depending on the plugin’s exposed endpoints.
OpenCVE Enrichment