Impact
The vulnerability is a missing authorization flaw in the Appointment Booking Calendar plugin that allows users to access functions not properly restricted by ACLs. This flaw, classified as CWE‑862, means an attacker could invoke privileged plugin operations without proper permission checks. The impacted functionality includes any feature exposed by the plugin that should be protected, potentially granting unauthorized configuration changes or data manipulation, thereby threatening confidentiality, integrity, and availability of the WordPress site.
Affected Systems
The issue affects the Codepeople Appointment Booking Calendar plugin version 1.3.92 and earlier. Any WordPress site running this plugin during that version range is susceptible. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% implies a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that the attack vector is a remote web application attack where an unauthenticated or low‑privilege user can trigger the exposed functionality, though the exact entry point is not specified in the advisory.
OpenCVE Enrichment
EUVD