Impact
The Booking for Appointments and Events Calendar WordPress plugin, in versions prior to 9.7, fails to verify that an authenticated employee is authorized to access a customer's data. This flaw allows any logged‑in employee with access to the Employee Panel to read or modify the personal data of any customer by simply enumerating sequential record identifiers. The vulnerability results in unauthorized disclosure and alteration of customer information, compromising confidentiality and integrity.
Affected Systems
Affected systems are WordPress websites that use the Amelia Pro plugin before version 9.7. Only plugin version information is available; there is no vendor-provided product list, but the plugin is widely known in the WordPress ecosystem.
Risk and Exploitability
The severity is high: an attacker can gain full access to any customer's personal data without needing elevated privileges beyond a normal employee login. While EPSS data is unavailable, the lack of an access control check makes exploitation straightforward. The vulnerability is not listed in CISA’s KEV catalog, but the potential for widespread data breaches warrants immediate attention. The likely attack vector is through the Employee Panel, with exploitation possible by sequential ID enumeration once an employee credential is known.
OpenCVE Enrichment