Impact
This vulnerability represents a broken access control flaw (CWE‑862) in the WpBookingly plugin. It permits an attacker to bypass the plugin’s built‑in authorization checks and gain unauthorized access to features intended for privileged users. While the advisory does not enumerate all exposed data, an attacker could potentially read, modify, or delete booking information and gain administrative capabilities.
Affected Systems
The affected product is the WordPress WpBookingly plugin from Magepeople inc. All releases up to and including version 1.2.9 are impacted. The plugin runs within WordPress sites, so any site hosting a vulnerable WpBookingly installation is at risk.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate severity, reflecting the fact that the exposure is limited to authorization bypass rather than arbitrary code execution. The EPSS score is unavailable, so there is no quantified measurement of the current exploit likelihood, but the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is likely web‑based; an adversary can send crafted HTTP requests to the plugin’s endpoints to acquire higher‑level privileges. Successful exploitation would give the attacker unauthorized control over booking processes and potentially sensitive data.
OpenCVE Enrichment