Impact
The MotoPress Appointment Booking WordPress plugin before 2.4.8 accepts a booking identifier from an unauthenticated user on a public endpoint and performs no authorization or ownership check, allowing an attacker to permanently delete any reservation. The flaw results in integrity loss of reservation data and can disrupt service for users who have already paid or are waiting for confirmation. It does not provide the attacker with information about the site or other data, but the impact on the application state and user trust is significant.
Affected Systems
Any installation of MotoPress Appointment Booking for WordPress running a plugin version earlier than 2.4.8 is affected. The vulnerability remains present on sites using payment confirmation mechanisms up through version 2.4.7, regardless of additional configuration.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of authentication on the deletion endpoint and the absolute need for no credentials suggest a high likelihood of exploitation in a production environment. The CVSS score is not provided, but the combination of unrestricted access and the irreversible effect of deleting reservations would lead evaluators to assign a severe rating. Attackers could simply send a crafted HTTP request to the deletion endpoint with a target booking ID from any device, requiring only network access to the WordPress site.
OpenCVE Enrichment