Impact
The EduAdmin Booking plugin for WordPress has an unauthenticated broken authentication flaw that allows attackers to log in without proper credentials. This defect is rooted in a weak authentication implementation, identified as CWE-288. Successful exploitation could enable an attacker to gain administrative capabilities and alter or delete booking data, potentially exposing sensitive user information and compromising the entire booking system.
Affected Systems
Affected systems are installations of the WordPress EduAdmin Booking plugin version 5.4.2 or earlier, distributed by Chris Åkerfeldt Wendel. The vulnerability is present in all versions of the plugin up to and including 5.4.2. Users of these versions should verify their plugin version and upgrade to the recommended minimum of 6.0.0.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity and indicates full remote exploitation with no authentication required. The EPSS score is unavailable, but the high CVSS and lack of mitigation in the current releases suggest a high likelihood of exploitation once discovered. The vulnerability is not listed in KEV, meaning there are no confirmed large‑scale exploits reported yet. The likely attack vector is remote web‑based, inferred from the unauthenticated nature of the flaw.
OpenCVE Enrichment