What the vulnerability does
01Description
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
Explanation of Vulnerability in Simple Terms
WpBookingly versions up to 1.2.9 lack proper authorization checks, allowing authenticated users to modify booking data they should not have access to. An attacker with a low-privilege account can alter bookings belonging to other users or administrators. The vulnerability requires login credentials but does not require user interaction beyond normal site usage.
What an attacker can do
Modify or tamper with booking records belonging to other users or administrators.
Potential impact on your site
Booking data integrity is compromised; users' reservations can be altered by other authenticated users without authorization.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities