Sceawere
Vulnerability Detail
CVE-2026-97079UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Webba Booking Subscriber IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- Webba Appointment Booking
- Product
- Webba Booking
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T13:17:34.730Z",
"pubdate": "2026-09-30T13:17:34.730Z",
"executiveSummary": "Webba Booking versions 6.5.0 and earlier are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability.\nThis flaw resides within the application's access control mechanisms, allowing authenticated users with the subscriber role to interact with objects or data they are not authorized to access.\nBy manipulating specific parameters in HTTP requests, an attacker can bypass authorization checks, potentially leading to unauthorized data disclosure, modification, or deletion of sensitive booking records.\nThe vulnerability poses a significant risk to data integrity and confidentiality within the booking management system.\nExploitation requires the attacker to have at least a subscriber-level account on the WordPress installation, making this a vulnerability that leverages existing user privileges to perform unauthorized actions beyond their intended scope.\nSuccessful exploitation allows attackers to perform actions on behalf of other users or administrators, compromising the overall security posture of the platform.",
"technicalDetails": "The vulnerability is a classic IDOR implementation flaw where the application fails to perform adequate server-side authorization checks on user-supplied input before performing operations on database records.\nThe root cause lies in the application's failure to validate that the currently authenticated subscriber has ownership or explicit permission to access or modify the requested booking resource identified by an ID parameter.\nIn Webba Booking <= 6.5.0, specific API endpoints or AJAX handlers responsible for managing bookings accept direct object references, such as a booking ID, via URL parameters or POST data. Because the system does not enforce strict Access Control Lists (ACLs) or verify the relationship between the session user and the resource ID, an attacker can substitute the ID with one belonging to another user.\nThe attack flow follows a predictable pattern: 1) The attacker authenticates as a standard subscriber. 2) The attacker intercepts legitimate requests made by the application to the booking management module using a proxy tool. 3) The attacker identifies the parameter responsible for object identification (e.g., booking_id). 4) By systematically incrementing or modifying the value of this parameter, the attacker probes the application for unauthorized access to other records.\nUpon successful exploitation, the backend processes the request as if it originated from a privileged user, effectively bypassing the intended security constraints of the WordPress 'subscriber' role.\nThe impact of this vulnerability includes the unauthorized retrieval of PII (Personally Identifiable Information) contained within booking forms, the modification of existing appointments, or the cancellation of bookings belonging to other users or administrators.\nThe vulnerability is exposed via the web interface and is accessible over any network where the booking system is reachable. Because the system performs operations server-side without verifying session-to-object ownership, the exploitation is reliable and does not require complex bypass techniques beyond parameter manipulation."
}