Impact
The vulnerability is an unauthenticated broken access control that allows an attacker to bypass permission checks in the Appointment Hour Booking plugin for WordPress. This flaw enables unauthorized use of the plugin's functionality, potentially exposing or altering sensitive scheduling information without requiring any authentication.
Affected Systems
The affected system is the WordPress plugin Appointment Hour Booking, version 1.5.91 or earlier, distributed by codepeople. Users running any of these versions on a WordPress site are impacted.
Risk and Exploitability
With a CVSS base score of 6.5 the vulnerability is considered moderately severe. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is remote, via the public‑facing WordPress site, and the attacker does not need authentication to exploit the flaw.
OpenCVE Enrichment