Impact
The vulnerability in WordPress BookIt versions up to 2.6.0.3 allows an attacker to bypass authentication controls without needing valid credentials, which means any person with network access to the WordPress site could potentially exploit the flaw to view or modify booking data or trigger plugin functions meant for authenticated users. The weakness is a form of improper authentication (CWE-345), which can lead to unauthorized data exposure or unauthorized modification of bookings, affecting the confidentiality and integrity of the booking system. No confirmation of remote code execution is given; the impact is confined to accessing or manipulating booking operations that should be restricted to logged‑in users.
Affected Systems
Vendors and products affected are the WordPress BookIt plugin from Nexcess (BookIt). Only the 2.6.0.3 release and earlier versions are impacted. Versions newer than 2.6.0.4 are not affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. EPSS information is not available, so the likelihood of exploitation cannot be quantified at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. The likely attack vector is any unauthenticated HTTP request to the WordPress site that interacts with the BookIt plugin. Without additional elevation steps, an attacker can use the plugin’s exposed endpoints to access or manipulate booking information. The scope of impact is limited to the affected WordPress site’s booking system.
OpenCVE Enrichment