Impact
This vulnerability is a broken access control flaw in the WordPress Booked plugin that allows authenticated users with the subscriber role to invoke functionality intended for higher‑privileged users. Based on the description, it is inferred that an attacker could send crafted HTTP requests to protected endpoints, enabling them to view, modify, or delete booking data and potentially alter site configuration, thereby compromising the integrity and availability of the system.
Affected Systems
WordPress sites that have the ThemeREX Booked plugin version 3.0.0 or earlier installed. No other plugins or WordPress core components are of the plugin.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation. The vulnerability is not listed in CISA KEV. An authenticated subscriber who can reach the vulnerable WordPress’s endpoints; the likely attack vector is via normal network access to the plugin’s endpoints.
OpenCVE Enrichment