Impact
The Appointment Booking Plugin for WordPress versions prior to 5.6.3 rejects CSRF nonce validation on several state‑changing actions handled by its central request dispatcher. This flaw allows an attacker to trigger privileged actions—such as overwriting booking‑form configuration or disconnecting a payment gateway—when a logged‑in administrator visits a malicious site. The vulnerability directly enables unauthorized modification of application state, which can disrupt booking services and potentially result in financial loss or denial of service if configuration files are altered.
Affected Systems
Any WordPress installation that uses the Appointment Booking Plugin older than 5.6.3 is exposed. The CNA identifies the affected product simply as "Appointment Booking Plugin"; no additional vendor or product identifiers are available beyond the plugin name.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk, while the EPSS score of less than 1% suggests that active exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker leveraging an active administrator session or tricking a logged‑in administrator to visit a malicious URL; this is inferred because the description notes a missing CSRF nonce on state‑changing actions. Thus, no additional preconditions beyond an authenticated admin are required, inferred from the described behavior.
OpenCVE Enrichment