Impact
The vulnerability is a cross‑site request forgery flaw in the FasterThemes FastBook appointment booking plugin for WordPress. An attacker, by sending or embedding a malicious request, can cause a logged‑in user to perform actions such as creating, modifying, or deleting appointments without consent. Because the flaw does not permit arbitrary code execution, the impact is limited to unauthorized use of the plugin’s functionality, potentially resulting in data tampering or service disruption.
Affected Systems
WordPress sites that have the FasterThemes FastBook plugin version 1.1 or earlier. The issue exists in all releases up to and including 1.1, from an unknown initial version through the listed threshold.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred from the description: an authenticated user must be logged into the WordPress admin area and then be induced to visit a crafted URL or submit a forged form from another site; without such conditions the attack fails, lowering both likelihood and impact.
OpenCVE Enrichment
EUVD