Impact
The Bus Ticket Booking with Seat Reservation WordPress plugin suffers from an unauthenticated Insecure Direct Object Reference flaw that allows attackers to tamper with request parameters and access protected reservation data. Because the vulnerability does not require prior authentication, an attacker can view or modify booking details, leading to potential data leakage, tampering of seat allocations, and operational disruption. The underlying weakness is captured by CWE‑639, which highlights inadequate protection of object identifiers in request handling.
Affected Systems
WordPress users who have installed the Bus Ticket Booking with Seat Reservation plugin by MagePeopleTeam, versions up to and including 5.9.3. The plugin provides seat reservation functionality for event and transportation booking sites running on WordPress. Users running any of these vulnerable versions are exposed until they upgrade to 5.9.4 or later.
Risk and Exploitability
The CVSS score of 6.5 marks the issue as medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation campaigns yet. However, the attack path is straightforward—an attacker sends crafted payloads that substitute resource identifiers in URLs or form fields, requiring no credentials. Consequently, the risk is elevated for sites that expose the plugin’s booking endpoints to public users or untrusted actors. Given the moderate CVSS rating and the absence of exploitation data, administrators should treat the vulnerability as a medium‑risk weakness and address it promptly. In the absence of a public exploit, potential attackers still could discover and leverage the IDOR by simple request modification tools.
OpenCVE Enrichment