CVE-2025-66530: WordPress Webba Booking plugin <= 6.2.1 - Broken Access Control vulnerability
Published Dec 9, 2025
·Updated
Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 6.2.1.
Affected Software
2 affected components
Webba Webba Booking<=6.2.1
wordpress/webba-booking<=6.2.1
Event History
Dec 9, 2025
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Nov 30, 58290
Event
via MITRE·07:16 PM