Description
Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Webba Booking: from n/a through 6.4.13.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Webba Booking plugin suffers from a Missing Authorization flaw (CWE‑862) that allows bypass of intended access controls for booking‑management functions. The description indicates that incorrectly configured access control security levels can be exploited, but it does not state the exact actions an attacker could perform. The CVSS score of 5.3 indicates moderate severity, meaning the vulnerability does not lead to remote code execution but can compromise the integrity and confidentiality of booking data.

Affected Systems

The affected product is the Webba Booking plugin from Webba Plugins. Versions from the earliest revision through 6.4.13 are vulnerable. Any WordPress site installing any of these versions is at risk until the plugin is updated to 6.4.14 or newer.

Risk and Exploitability

The moderate CVSS score of 5.3 combined with an EPSS of < 1 % suggests a low likelihood of exploitation. The likely attack vector, inferred from the plugin’s design of exposing endpoints for booking management, involves sending HTTP requests to these endpoints. While the description does not directly confirm that unauthenticated users can exploit the flaw, it is inferred that lack of authorization checks may allow both unauthenticated or low‑privilege users to gain unauthorized access. The vulnerability is not listed in KEV, so active exploitation has not been documented, yet the potential for unauthorized modification of booking data remains.

Generated by OpenCVE AI on July 21, 2026 at 14:00 UTC.

Remediation

Vendor Solution

Update the WordPress Webba Booking Plugin to the latest available version (at least 6.4.14).


OpenCVE Recommended Actions

  • Update the Webba Booking plugin to version 6.4.14 or later.
  • Ensure that only users with administrative privileges can access booking‑management pages and API endpoints.
  • Audit any custom or third‑party endpoints that expose booking data and apply proper authorization checks or remove them.

Generated by OpenCVE AI on July 21, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.
Title WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T17:34:50.305Z

Reserved: 2026-02-19T09:52:22.262Z

Link: CVE-2026-27409

cve-icon Vulnrichment

Updated: 2026-07-01T17:34:47.503Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:15:04Z

Weaknesses