Executive brief
A security vulnerability exists in the WP Booking System plugin for WordPress, which is used to manage reservations and appointments. An attacker with a basic user account, such as a subscriber, can bypass security restrictions to perform actions they should not be authorized to do. This could allow unauthorized changes to booking data or system settings, potentially disrupting business operations and reservation management.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the WP Booking System plugin for WordPress in versions prior to 5.12.8.1. The flaw resides in a failure to properly validate user permissions or implement sufficient authorization checks on certain functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this over the network to execute higher-privileged actions, leading to unauthorized data modification or partial service disruption. The issue is addressed in version 5.12.8.1.
Affected products
- WP Booking System WP Booking System < 5.12.8.1
Timeline
- 2026-05-15: other: Reported by Austin Ginder
- 2026-07-06: patched: Patch released in version 5.12.8.1
- 2026-07-23: disclosed: CVE published to NVD