Impact
The vulnerability is a missing authorization flaw that enables attackers to perform actions that should be restricted. The flaw is categorized under CWE-862 and can lead to unauthorized operations within the WordPress site, potentially exposing sensitive data or allowing further exploitation. The description specifies that incorrectly configured access control levels are the root cause, so the potential impact is the loss of integrity and confidentiality for privileged content or functions.
Affected Systems
This issue affects the WordPress WPBookit Pro plugin from iqonicdesign, versions ranging from the very first release up to and including 1.6.18. Users should verify that they are running a version later than 1.6.18 to avoid the vulnerability.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity risk. The EPSS score is below 1%, suggesting a low likelihood of exploitation at the present time. The vulnerability is not listed in the CISA KEV catalog, so it is not known to be widely exploited. The attack vector is not explicitly documented in the provided data, but based on the description of a missing authorization check, the likely vector involves authenticated users or publicly accessible endpoints where access levels are improperly enforced. Exposing administrative functions to lower‑privileged actors is the primary pathway. CHP
OpenCVE Enrichment