Description
Missing Authorization vulnerability in bookingalgorithms BA Book Everything ba-book-everything allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BA Book Everything: from n/a through <= 1.8.16.
Published: 2026-01-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control leading to unauthorized actions
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization defect that allows attackers to exploit incorrectly configured access control security levels in the BA Book Everything plugin. This flaw can enable users who should not have permission to perform restricted actions, effectively leading to privilege escalation and unauthorized manipulation of booking data. The underlying weakness corresponds to CWE‑862, a classic broken access control issue.

Affected Systems

The plugin is affected in all WordPress installations running BA Book Everything version 1.8.16 or earlier. Any site that has the plugin installed without upgrading past this version is at risk. The issue is noted from "n/a" through the stated upper bound, meaning all previous releases lack the fix.

Risk and Exploitability

The CVSS score of 9.8 marks this flaw as critical, reflecting a high impact and widespread availability. The EPSS score of less than 1 percent indicates that, although the vulnerability is severe, the current likelihood of exploitation in the wild is very low. It is not yet listed in the CISA KEV catalog. The plugin functions through the WordPress web interface, so the inferred attack vector is remote, via authenticated or unauthenticated web requests, depending on the plugin’s exposed endpoints.

Generated by OpenCVE AI on April 16, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update BA Book Everything to the latest version above 1.8.16 to address the broken access control flaw
  • If an immediate update is not possible, disable or uninstall the plugin to remove the attack surface
  • After patching or removal, review and tighten role-based permissions within WordPress to ensure that only intended users have access to booking management duties

Generated by OpenCVE AI on April 16, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 26 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Booking Algorithms
Booking Algorithms ba Book Everything
Wordpress
Wordpress wordpress
Vendors & Products Booking Algorithms
Booking Algorithms ba Book Everything
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in bookingalgorithms BA Book Everything ba-book-everything allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BA Book Everything: from n/a through <= 1.8.16.
Title WordPress BA Book Everything plugin <= 1.8.16 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Booking Algorithms Ba Book Everything
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-23T14:14:04.984Z

Reserved: 2026-01-22T14:42:32.873Z

Link: CVE-2026-24371

cve-icon Vulnrichment

Updated: 2026-01-23T16:47:53.165Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:40.423

Modified: 2026-04-23T15:36:43.703

Link: CVE-2026-24371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T02:15:21Z

Weaknesses