Impact
The vulnerability resides in a WordPress plugin that fails to verify ownership before exposing order details. An attacker can request arbitrary order-item identifiers and obtain a customer’s name, contact details, and order confirmation code. This results in a privacy breach for every user whose order data is exposed, allowing the attacker to collect personally identifiable information without authentication.
Affected Systems
Any WordPress site that has the Appointment Booking Plugin installed and running a version earlier than 5.7.3 is affected. The plugin’s vendor is unknown from the available data; therefore, all installations of the plugin before the stated version must be evaluated for risk.
Risk and Exploitability
The listed CVSS score is not provided, but the vulnerability is exploitable by unauthenticated visitors who supply sequential order-item identifiers. Because the plugin does not perform an ownership check, the attack requires only a web request and no privileged access, making it very low‑barrier. The absence of an EPSS score or KEV listing suggests that exploitation has not yet been widely observed, but the inherent privacy impact remains high. The likelihood of exploitation is difficult to quantify, yet any site with this plugin version remains vulnerable until the fix is applied.
OpenCVE Enrichment