GetBookingsWP Plugin Broken Access Control Vulnerability
Vulnerability
A broken access control vulnerability has been identified in the GetBookingsWP WordPress plugin, affecting versions through 1.1.27. This vulnerability arises from missing authorization checks, allowing users with lower privileges to perform actions reserved for higher privileged users.
Impact
Exploitation of this vulnerability could allow users with subscriber privileges to access or modify data or functionality that should be restricted.
Remediation
Users of the GetBookingsWP WordPress plugin are advised to update to the latest version. Patchstack has issued a virtual patch to mitigate this vulnerability until an official fix is available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
