Impact
Cross‑Site Request Forgery in the Appointy Appointment Scheduler plugin allows an attacker to change plugin settings without authentication. The flaw permits alteration of scheduling options, user permissions, or feature toggles, compromising both configuration integrity and service availability. The weakness is identified as CWE‑352 and is a moderate‑severity vulnerability with a CVSS score of 6.5.
Affected Systems
WordPress installations running the Appointy Appointment Scheduler plugin version 4.2.1 or earlier are affected. No other vendors or products are listed.
Risk and Exploitability
The exploit probability is very low with an EPSS score of less than 1 %. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Likely attack vectors involve a malicious website tricking an authenticated admin user into visiting a crafted URL that triggers a settings change. No advanced prerequisites beyond the target WordPress environment are required.
OpenCVE Enrichment
EUVD