CVE-2026-97079: WordPress Webba Booking plugin <= 6.5.0 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 30, 2026
·Updated
Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.
Affected Software
1 affected component
Webba Webba Booking<=6.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Webba Booking pluginto a version that resolves this vulnerability.Fixed in 6.5.2
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as affecting Subscriber-level users, and the CVSS vector requires low privileges (PR:L). An attacker therefore needs an authenticated account with at least low-level access.
2
What is the likely impact if exploited?
The CVSS vector indicates low confidentiality impact, with no stated integrity or availability impact. This suggests unauthorized access to information rather than modification or service disruption.
3
Which plugin versions are affected?
Webba Booking versions up to and including 6.5.0 are identified as affected.