Impact
The MotoPress Appointment Booking WordPress plugin before 2.4.8 accepts a booking identifier from an unauthenticated user on a public endpoint and performs no authorization or ownership check, allowing an attacker to permanently delete any reservation. This flaw results in integrity loss of reservation data and can disrupt service for users who have already paid or are waiting for confirmation. It does not provide the attacker with information about the site or other data, but the impact on the application state and user trust is significant.
Affected Systems
Any installation of MotoPress Appointment Booking for WordPress running a plugin version earlier than 2.4.8 is affected. The vulnerability remains present on sites using payment confirmation mechanisms up through version 2.4.7, regardless of additional configuration.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability that attackers will find and exploit this vulnerability in the current year. The CVSS score of 5.3 classifies the flaw as moderate severity due to the lack of authentication on a public deletion endpoint, but the inability to prove attacks in the wild reduces overall risk. Attackers would still need to identify a valid booking identifier to target, and many sites may have monitoring or rate limits that reduce the chance of successful deletions.
OpenCVE Enrichment