Impact
The vulnerability is an Insecure Direct Object Reference that allows an attacker to manipulate a parameter identifying an internal object, such as a booking entry, within the Webba Booking plugin. This flaw can lead to unauthorized viewing or modification of booking data, potentially exposing sensitive subscriber information. The weakness is classified as CWE-639, which highlights improper authorization checks.
Affected Systems
The affected product is the WordPress Webba Booking plugin, versions up to and including 6.5.0. Administrators of WordPress sites that have installed these plugin versions should verify their installation and update where possible.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via the web application, where an attacker could supply crafted requests to access or modify booking objects. Based on the description, it is inferred that the vulnerability does not require special privileges, meaning the impact could be broader than a single user but does not necessarily compromise full system integrity.
OpenCVE Enrichment