Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin versions up to 4.6.0. Attackers who do not possess valid credentials can bypass normal access restrictions and reach privileged administrative endpoints. This flaw can allow the attacker to view, modify, or delete booking data and potentially perform other privileged operations normally reserved for site administrators. The weakness falls under the Unrestricted Access to a Sensitive Resource category (CWE-862).
Affected Systems
The affected product is the WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin, with all releases equal to or earlier than version 4.6.0. The vulnerability is reported for all installation environments running one of the affected versions on a WordPress site.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating significant impact if exploited. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, suggesting that publicly known exploit code may not yet exist. Exploitation is likely possible through the plugin's exposed web interfaces without authentication, giving an unauthenticated attacker the ability to access privileged functions. Because access is unauthenticated, a widespread attack vector is the publicly accessible WordPress admin URLs that the plugin injects.
OpenCVE Enrichment