Impact
JetBooking plugin for WordPress versions up to 4.1.2 has an unauthenticated broken access control flaw. This weakness, classified as CWE-862, permits an attacker to bypass authorization checks when accessing booking data. The vulnerability allows viewing of booking resources that an unauthenticated user should not see. No additional capabilities are stated in the description.
Affected Systems
The flaw affects the JetBooking plugin distributed by Crocoblock and Jetimpex Inc. Any WordPress site running JetBooking version 4.1.2 or earlier is vulnerable. The vulnerability pertains to the plugin and is not known to impact other WordPress components.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote via the public-facing WordPress interface, and the attacker does not require any existing credentials to exploit.
OpenCVE Enrichment