Impact
The vulnerability is an unauthenticated Insecure Direct Object Reference (CWE-639) that allows attackers to manipulate or read appointment data stored by the Booking calendar, Appointment Booking System plugin. By supplying a crafted request to the plugin’s endpoints, an attacker can potentially view, edit, or delete arbitrary booking records; the plug‑in does not validate that the requesting user owns the referenced resource. This can expose sensitive user or service information and compromise the integrity of the booking system.
Affected Systems
The affected product is the WordPress plugin Booking calendar, Appointment Booking System developed by wpdevart. Any site running version 3.2.36 or earlier is vulnerable. Versions newer than 3.2.36 are not affected according to the provided data.
Risk and Exploitability
The CVSS base score is 6.5, indicating a medium severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in known attacks. The likely attack vector is remote via HTTP requests to the plugin’s admin or API endpoints; authentication is not required, so an unauthenticated attacker can exploit this weakness directly from the web interface. The risk remains moderate but given the potential impact on privacy and data integrity, timely remediation is advised.
OpenCVE Enrichment