CVE-2025-54040: WordPress Webba Booking <= 5.1.20 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Webba Appointment Booking Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 5.1.20.
Other sources
Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 5.1.20.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54040?
CVE-2025-54040 is rated as a critical vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2025-54040?
To fix CVE-2025-54040, update Webba Booking to version 5.1.21 or later to ensure proper access control settings.
Which versions of Webba Booking are affected by CVE-2025-54040?
CVE-2025-54040 affects Webba Booking versions up to and including 5.1.20.
What is the impact of exploiting CVE-2025-54040?
Exploitation of CVE-2025-54040 could allow attackers to gain unauthorized access to features or data within the Webba Booking application.
Is there a workaround for CVE-2025-54040 while waiting for a patch?
As a temporary workaround for CVE-2025-54040, review and tighten access controls manually until the application is updated.