Impact
This vulnerability allows an unauthenticated attacker to read appointment data from a WordPress site that runs WooCommerce Appointments version 5.3.8 or earlier. The weakness is an information disclosure flaw that exposes private user and booking information, violating confidentiality. The identified weakness corresponds to CWE‑497, which addresses information exposure due to missing authentication.
Affected Systems
The affected product is the BookingWP WooCommerce Appointments plugin for WordPress. Versions up to and including 5.3.8 are vulnerable. Individual sites that have older versions installed are at risk.
Risk and Exploitability
The CVSS base score of 7.5 classifies the vulnerability as high severity. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. The flaw can be exploited remotely by sending an unauthenticated request to the vulnerable endpoint, resulting in disclosure of sensitive data. Because the attack vector does not require any special privileges, the risk to sites that expose appointment data is significant.
OpenCVE Enrichment