Impact
The vulnerability allows a subscriber to gain elevated privileges within the WordPress site by exploiting a flaw in the WP BASE Booking plugin. No further details on the attacker’s scope are provided. The issue is classified as CWE‑266, indicating improper access control.
Affected Systems
The affected product is the WP BASE Booking plugin developed by Hakan Ozevin. Versions up to and including 6.3.1 are vulnerable; any installation of these or earlier revisions should be updated.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of <1% reflects a low likelihood of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog, suggesting no currently known widespread exploitation. Attackers would need to log in as a subscriber to the WordPress site and use the plugin’s functionality, implying the attack vector is through legitimate user interactions with the plugin interface.
OpenCVE Enrichment