Impact
This vulnerability is a missing authorization flaw in the WordPress Pinpoint Booking System plugin that allows an attacker to reach functions or data that are intended to be protected. The weakness permits unauthorized use of access controls, potentially exposing sensitive booking information or enabling operations that should be reserved for privileged users.
Affected Systems
The defect affects the DOTonPAPER Pinpoint Booking System plugin for WordPress versions from the earliest available through 2.9.9.6.5. Any WordPress site that has this plugin installed in a vulnerable version is subject to risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves remote interaction via HTTP requests that target the plugin's endpoints without proper role checks; the specific exploitation details are not disclosed but are implied by the missing authorization mechanism.
OpenCVE Enrichment