Impact
The vulnerability is a missing authorization flaw in the wpdevart Booking calendar, Appointment Booking System plugin that lets attackers bypass the intended access control checks. Classified as CWE-862, it enables an unauthenticated or low‑privilege user to read, modify, or delete booking information, thereby compromising the confidentiality and integrity of scheduling data.
Affected Systems
All installations of the WordPress Booking calendar, Appointment Booking System plugin by wpdevart with versions up to and including 3.2.36 are affected. The issue does not appear in later versions.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the plugin’s web‑based nature, the attack vector is inferred to be remote: an attacker could send crafted HTTP requests to the plugin’s admin endpoints to trigger privileged actions without proper authentication. No publicly disclosed exploit code is available, but the flaw could be leveraged by threat actors with moderate skill.
OpenCVE Enrichment