Impact
WP Booking System plugin versions prior to 5.12.8.1 contain a broken access control flaw that allows authenticated subscribers to perform functions reserved for higher privileged users. This vulnerability can lead to unauthorized creation or modification of booking entries, potentially exposing sensitive data or disrupting service. The weakness is identified as CWE‑862, a broken access control issue.
Affected Systems
The issue affects the WordPress WP Booking System plugin, version 5.12.8.1 and earlier, installed on WordPress sites that use this plugin. All users with subscriber-level accounts on affected installations are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% suggests the current probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that the attacker be an authenticated subscriber, making the attack vector likely through normal web interaction with the booking system interface.
OpenCVE Enrichment