Impact
The JetBooking plugin for WordPress contains a Server Side Request Forgery (SSRF) flaw in versions 4.1.2 and earlier. The vulnerability originates from a custom role that the plugin uses to trigger outbound HTTP requests to arbitrary URLs. If an attacker controls a user account that holds this custom role, they can instruct the server to send requests to internal or external resources, potentially exposing sensitive data or enabling further attacks against network services. The weakness is identified as CWE‑918, which highlights the lack of proper validation of the target URL.
Affected Systems
The flaw affects installations of the JetBooking plugin developed by Crocoblock and Jetimpex Inc. for WordPress sites. Versions 4.1.2 or earlier are vulnerable; any site running those releases is susceptible, especially if a user is granted the custom role that can trigger SSRF.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of real‑world exploitation at this time. The vulnerability is not listed in CISA's KEV catalog. An attacker can exploit the flaw by accessing the plugin’s interfaces or functional endpoints that utilize the custom role. Once activated, the server can reach arbitrary URLs, potentially accessing internal network resources or extracting sensitive data.
OpenCVE Enrichment