Impact
This vulnerability is a Cross Site Request Forgery (CSRF) flaw in the Appointify WordPress plugin that allows an attacker to trick a logged‑in user into submitting a request that the site will accept as legitimate. The effect is the potential for malicious scheduling, data manipulation, or other actions that the authenticated user is permitted to perform, thereby compromising the integrity of the appointment system.
Affected Systems
WordPress sites that have installed Appointify versions 1.0.8 or earlier are affected. No other vendors or products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while an EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, and the attack requires a victim who is authenticated to the target site, making the threat vector a web‑based CSRF action. Given these factors, the overall risk is moderate, but remediation is recommended to prevent potential unauthorized use of the appointment system.
OpenCVE Enrichment