Impact
The vulnerability originates from the Booking for Appointments and Events Calendar WordPress plugin. Prior to version 2.4.6, the plugin fails to confirm that an authenticated employee (provider) is actually assigned to an appointment before allowing them to view it. This flaw means that any logged‑in employee can read the personal details of any customer by supplying the appointment identifier. The impact is that confidential customer information—such as contact details, booking dates, and any personal notes—is exposed to unauthorised parties, potentially violating privacy and data protection regulations.
Affected Systems
WordPress sites running the Booking for Appointments and Events Calendar plugin with a version number earlier than 2.4.6. The vendor is unknown and the product is the plugin listed above.
Risk and Exploitability
No CVSS score has been published, and the EPSS score is currently unavailable, so precise quantification of risk is limited. The flaw requires the attacker to be an authenticated employee, which narrows the threat actor set to internal staff, but the impact is significant because it allows disclosure of personal customer data. Because the vulnerability is a classic IDOR, an attacker who discovers the pattern can easily enumerate appointment IDs and harvest data. The vulnerability is not yet listed in CISA KEV, but it should be considered a high‑risk exposure given the potential legal and reputational consequences.
OpenCVE Enrichment