Impact
The vulnerability originates from the Booking for Appointments and Events Calendar WordPress plugin. Prior to version 2.4.6, the plugin fails to confirm that an authenticated employee (provider) is actually assigned to an appointment before allowing them to view it. This flaw means that any logged‑in employee can read the personal details of any customer by supplying the appointment identifier. The impact is that confidential customer information—such as contact details, booking dates, and any personal notes—is exposed to unauthorised parties, potentially violating privacy and data protection regulations.
Affected Systems
WordPress sites running the Booking for Appointments and Events Calendar plugin with a version number earlier than 2.4.6. The vendor is unknown and the product is the plugin listed above.
Risk and Exploitability
The CVSS score of 3.7 assigns a low severity rating, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The flaw requires the attacker to be an authenticated employee, which limits the threat actor set to internal staff, but the impact is significant because it allows disclosure of personal customer data. Because the vulnerability is a classic IDOR, an attacker who discovers the pattern can easily enumerate appointment IDs and harvest data. The vulnerability is not listed in CISA KEV, but it should be considered a high‑risk exposure given potential legal and reputational consequences.
OpenCVE Enrichment