Impact
The vulnerability in Service Finder Booking allows a subscriber role to bypass access controls, potentially reaching functions and data that should only be available to higher‑privileged users. This broken access control flaw, classified as CWE‑862, can lead to unauthorized information disclosure or manipulation within the plugin.
Affected Systems
Vendors: Aonetheme. Affected product: Service Finder Booking plugin versions up to and including 6.2. Systems running these versions on WordPress sites are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. EPSS data is unavailable, and the vulnerability is not listed in KEV, suggesting no known widespread exploitation. The likely attack vector is through the web interface of the WordPress site, where an attacker could access disabled or restricted URLs by elevating a subscriber role to act as an administrator. This exploit requires remote access to the site and legitimate user authentication or the ability to forge requests to the plugin’s endpoints.
OpenCVE Enrichment