Impact
The Easy Appointments WordPress plugin before version 3.12.28 does not perform any capability or nonce check in one of its connection‑deletion actions, enabling users with contributor‑level access to delete the entire booking configuration and thus disable the booking system. This represents an authorization bypass (CWE‑284) that results in loss of service availability and loss of configuration data.
Affected Systems
WordPress sites that install Easy Appointments up to and including version 3.12.27. The plugin is distributed as a WordPress plugin under the Easy Appointments name, and no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 3.8 classifies this vulnerability as low severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not catalogued in the CISA KEV list. Attackers would need to obtain a contributor‑level login to a WordPress site that uses the affected plugin, and then trigger the connection‑deletion action. Because the flaw is limited to plugin file operations and does not provide remote code execution, the risk to confidentiality or integrity is minimal; the primary risk is to availability and configuration.
OpenCVE Enrichment