Impact
The vulnerability is a broken access control flaw in the QuickCal – Appointment Booking Calendar for WordPress plugin. An attacker who is able to exploit the flaw could perform privileged operations without proper authorization, potentially creating or removing appointments, accessing sensitive booking data, or modifying user information. The weakness is classified as CWE-862, which focuses on unauthorized access to privileged functionality. The description unauthorized actions.
Affected Systems
The affected product is QuickCal – Appointment Booking Calendar for WordPress from Axiom Themes. Versions up to and including 1.0.16 are vulnerable. No additional vendors or product versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. The EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale exploit activity. Based on the plugin’s web‑based nature, the likely attack vector is remote via the WordPress administration, inferred from the nature of access system, either with existing credentials or through a form that does not enforce proper user roles, to execute privileged actions. The above metrics and inferred attack path represent the current risk assessment.
OpenCVE Enrichment