What the vulnerability does
01Description
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
What the vulnerability does
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The Accommodation System WordPress plugin version 1.0.1 and earlier contains an authorization flaw that allows authenticated users with low privileges to read sensitive data and make limited modifications to the site. An attacker with a standard user account can access information they should not be able to view and alter certain site settings. The vulnerability requires an active user account but no additional user interaction.
What an attacker can do
Read sensitive data and make limited changes to site settings with a low-privilege user account.
Potential impact on your site
Unauthorized users can access confidential information and modify site configuration, potentially exposing guest data or disrupting bookings.
Conditions required to exploit
Attacker must have a valid WordPress user account with low privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities