Impact
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 permits unauthenticated users to perform actions they should not be authorized for, potentially exposing or altering appointment data. This flaw is classified as CWE-862 and can lead to data disclosure and integrity compromise if exploited. The vulnerability allows an attacker to use plugin endpoints without authentication, granting privileged capabilities beyond their intended scope.
Affected Systems
WordPress TrueBooker plugin from theThemeTechMount with any version up to and including 1.1.9 is affected. The vulnerability exists in the plugin code that handles appointment operations. Users running these versions should treat them as vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity issue. The EPSS score of less than 1% suggests a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalogue, so no confirmed public exploits exist. Based on the description, the likely attack vector is through the site's public web interface where an unauthenticated user can trigger the plugin’s privileged functions without authentication.
OpenCVE Enrichment