Impact
The vulnerability is a missing authorization defect that allows attackers to exploit incorrectly configured access control security levels in the BA Book Everything plugin. This flaw can enable users who should not have permission to perform restricted actions, effectively leading to privilege escalation and unauthorized manipulation of booking data. The underlying weakness corresponds to CWE‑862, a classic broken access control issue.
Affected Systems
The plugin is affected in all WordPress installations running BA Book Everything version 1.8.16 or earlier. Any site that has the plugin installed without upgrading past this version is at risk. The issue is noted from "n/a" through the stated upper bound, meaning all previous releases lack the fix.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical, reflecting a high impact and widespread availability. The EPSS score of less than 1 percent indicates that, although the vulnerability is severe, the current likelihood of exploitation in the wild is very low. It is not yet listed in the CISA KEV catalog. The plugin functions through the WordPress web interface, so the inferred attack vector is remote, via authenticated or unauthenticated web requests, depending on the plugin’s exposed endpoints.
OpenCVE Enrichment