Impact
The Booking Calendar plugin for WordPress permits unauthenticated users to invoke an AJAX function that reveals detailed booking information, including customer names, phone numbers, and email addresses, because the function lacks a capability check. This missing authorization check leads to a confidentiality breach and corresponds to CWE‑862.
Affected Systems
WordPress sites running the wpdevelop:Booking Calendar plugin, versions up to and including 10.14.13, are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3 and an EPSS score of less than 1 %, indicating moderate severity but a low likelihood of exploitation. It is not listed in CISA’s Known Exploited Vulnerabilities catalog. The attack vector is an unauthenticated AJAX request; attackers only need access to the site’s public URL to retrieve sensitive booking data.
OpenCVE Enrichment