Impact
The Booking for Appointments and Events Calendar WordPress plugin, in versions prior to 9.7, fails to verify that an authenticated employee is authorized to access a customer's data. This flaw allows any logged‑in employee with access to the Employee Panel to read or modify the personal data of any customer by simply enumerating sequential record identifiers. The vulnerability results in unauthorized disclosure and alteration of customer information, compromising confidentiality and integrity.
Affected Systems
Affected systems are WordPress websites that use the Amelia Pro plugin before version 9.7. Only plugin version information is available; there is no vendor-provided product list, but the plugin is widely known in the WordPress ecosystem.
Risk and Exploitability
The CVSS score is 3.8, indicating a low severity: an attacker can gain full access to any customer's personal data without needing elevated privileges beyond a normal employee login. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is through the Employee Panel, with exploitation possible by sequential ID enumeration once an employee credential is known.
OpenCVE Enrichment