Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass authorization checks in the WordPress Booking and Rental Manager plugin. By exploiting this weakness, an attacker could view or modify booking and rental data that should be restricted to authenticated users, potentially compromising confidentiality and integrity of sensitive information.
Affected Systems
The issue affects the Booking and Rental Manager plugin developed by MagePeople Team. Versions 2.7.1 and earlier are vulnerable, regardless of the WordPress site or WooCommerce environment in which the plugin is installed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Likely attackers can exploit the flaw from any external web request without authentication, making the vulnerability accessible to anyone who can reach the affected WordPress site.
OpenCVE Enrichment