Impact
The vulnerability is caused by the create_order_permission callback returning true unconditionally and by find_and_update_guest overwriting an existing customer’s stored name, phone, and wp_user_id when the email matches, without confirming ownership. This allows an attacker to send a POST request to the /wp-json/booktics/v1/orders endpoint and overwrite any customer’s contact details if the attacker knows that customer’s email address. The attacker can poison the downstream reminder emails, SMS, calendar invites, and CRM data, potentially leading to miscommunication and privacy issues. The flaw is a missing authorization check (CWE‑862).
Affected Systems
WordPress sites that have the Booktics – Appointment Booking Calendar for Service Businesses plugin installed, any version up to and including 1.0.23, from the vendor arraytics.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by issuing unauthenticated POST requeststics/v1/orders with the target customer’s email. No authentication or privileged permissions are required, and the attack does not provide remote code execution. Because the defect lies in an authorization check, a successful exploit results in unauthorized data modification rather than system compromise.
OpenCVE Enrichment