Description
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a broken access control flaw in the WordPress Booked plugin that allows authenticated users with the subscriber role to invoke functionality intended for higher‑privileged users. Based on the description, it is inferred that an attacker could send crafted HTTP requests to protected endpoints, enabling them to view, modify, or delete booking data and potentially alter site configuration, thereby compromising the integrity and availability of the system.

Affected Systems

WordPress sites that have the ThemeREX Booked plugin version 3.0.0 or earlier installed. No other plugins or WordPress core components are of the plugin.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation. The vulnerability is not listed in CISA KEV. An authenticated subscriber who can reach the vulnerable WordPress’s endpoints; the likely attack vector is via normal network access to the plugin’s endpoints.

Generated by OpenCVE AI on July 22, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ThemeREX Booked plugin to the latest release containing the access‑control fix.
  • If an upgrade is impossible, consider uninstalling the plugin entirely to remove the vulnerable code.
  • If removal is not feasible, modify the subscriber role using a role‑editor plugin so that it cannot trigger the plugin’s protected actions, although this is a temporary measure.

Generated by OpenCVE AI on July 22, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Booked <= 3.0.0 versions.
Title WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:40:12.149Z

Reserved: 2026-06-25T08:04:29.579Z

Link: CVE-2026-57746

cve-icon Vulnrichment

Updated: 2026-07-02T19:40:06.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:45:02Z

Weaknesses