GetBookingsWP Plugin Broken Access Control Vulnerability

Vulnerability

A broken access control vulnerability has been identified in the GetBookingsWP WordPress plugin, affecting versions through 1.1.27. This vulnerability arises from missing authorization checks, allowing users with lower privileges to perform actions reserved for higher privileged users.

Impact

Exploitation of this vulnerability could allow users with subscriber privileges to access or modify data or functionality that should be restricted.

Remediation

Users of the GetBookingsWP WordPress plugin are advised to update to the latest version. Patchstack has issued a virtual patch to mitigate this vulnerability until an official fix is available.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.