Description
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WP Booking System plugin versions prior to 5.12.8.1 contain a broken access control flaw that allows authenticated subscribers to perform functions reserved for higher privileged users. This vulnerability can lead to unauthorized creation or modification of booking entries, potentially exposing sensitive data or disrupting service. The weakness is identified as CWE‑862, a broken access control issue.

Affected Systems

The issue affects the WordPress WP Booking System plugin, version 5.12.8.1 and earlier, installed on WordPress sites that use this plugin. All users with subscriber-level accounts on affected installations are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% suggests the current probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that the attacker be an authenticated subscriber, making the attack vector likely through normal web interaction with the booking system interface.

Generated by OpenCVE AI on August 3, 2026 at 22:32 UTC.

Remediation

Vendor Solution

Update the WordPress WP Booking System Plugin to the latest available version (at least 5.12.8.1).


OpenCVE Recommended Actions

  • Upgrade the WP Booking System plugin to version 5.12.8.1 or later.
  • Verify that all user roles have appropriate permissions; ensure that only administrators have access to protected booking functions.
  • Disable or remove the plugin on sites where it is not required, or enforce role restrictions via WordPress role management.

Generated by OpenCVE AI on August 3, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpbookingsystem
Wpbookingsystem wp Booking System
Vendors & Products Wordpress
Wordpress wordpress
Wpbookingsystem
Wpbookingsystem wp Booking System

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Title WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Wordpress Wordpress
Wpbookingsystem Wp Booking System
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:53:12.938Z

Reserved: 2026-06-24T12:45:46.645Z

Link: CVE-2026-57367

cve-icon Vulnrichment

Updated: 2026-07-23T13:53:09.879Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:27.910

Modified: 2026-07-23T14:17:23.743

Link: CVE-2026-57367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses