What the vulnerability does
01Description
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
Explanation of Vulnerability in Simple Terms
WpBookingly versions up to 1.2.9 lack proper authorization checks, allowing high-privilege users to modify or delete booking data without appropriate permission validation. An authenticated administrator can alter booking records, availability settings, or customer information through direct API or form manipulation. Sites using this plugin should update immediately to prevent unauthorized changes to critical booking functionality.
What an attacker can do
A high-privilege user can modify or delete booking data and settings without proper authorization checks.
Potential impact on your site
Booking records, availability, and customer data can be altered or deleted by any admin user, risking data integrity and customer trust.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities