Impact
The Webba Booking plugin suffers from a Missing Authorization flaw (CWE‑862) that allows bypass of intended access controls for booking‑management functions. The description indicates that incorrectly configured access control security levels can be exploited, but it does not state the exact actions an attacker could perform. The CVSS score of 5.3 indicates moderate severity, meaning the vulnerability does not lead to remote code execution but can compromise the integrity and confidentiality of booking data.
Affected Systems
The affected product is the Webba Booking plugin from Webba Plugins. Versions from the earliest revision through 6.4.13 are vulnerable. Any WordPress site installing any of these versions is at risk until the plugin is updated to 6.4.14 or newer.
Risk and Exploitability
The moderate CVSS score of 5.3 combined with an EPSS of < 1 % suggests a low likelihood of exploitation. The likely attack vector, inferred from the plugin’s design of exposing endpoints for booking management, involves sending HTTP requests to these endpoints. While the description does not directly confirm that unauthenticated users can exploit the flaw, it is inferred that lack of authorization checks may allow both unauthenticated or low‑privilege users to gain unauthorized access. The vulnerability is not listed in KEV, so active exploitation has not been documented, yet the potential for unauthorized modification of booking data remains.
OpenCVE Enrichment