Impact
The Booking for Appointments and Events Calendar plugin before version 9.8 allows an authenticated employee (provider) to update the password of any other provider account because the plugin does not verify ownership of the target account. This makes the vulnerability a classic IDOR flaw that can lead to the attacker gaining full control over the victim provider’s account and all associated data.
Affected Systems
WordPress sites that use the Booking for Appointments and Events Calendar plugin with a version earlier than 9.8 are affected. The weakness is present in the Employee Panel login functionality, which is typically accessible to users with employee credentials. No specific vendor name exists beyond the plugin itself; functionality is limited to provider account management within the plugin.
Risk and Exploitability
The exploit requires an authenticated session in the Employee Panel and does not require local or remote code execution. EPSS is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. However, the internal nature of the flaw means that once an employee account is compromised, an attacker can take over another provider’s account. The likely attack vector is an authorized user exploiting normal password change functionality or using a crafted request. Given the authentication requirement, the risk is moderate to high for sites with multiple provider accounts and without additional access controls.
OpenCVE Enrichment