Impact
The Appointment Booking Calendar Plugin and Scheduling Plugin before version 1.6.3 do not verify that the amount actually paid matches the server‑side price set for a booking when confirming an online PayPal payment. An unauthenticated attacker can therefore trigger the booking confirmation with a partial or incorrect payment amount, causing the system to record the appointment as fully paid for a fraction of its true cost.
Affected Systems
WordPress installations deploying the Appointment Booking Calendar Plugin or Scheduling Plugin with a version older than 1.6.3 are affected. The plugin is commonly used for booking scheduling and appointments, and the issue remains present in releases from 1.5.6 through 1.6.2.
Risk and Exploitability
Because the flaw is exploitable without authentication and the plugin is publicly available, the risk is high. The EPSS score of less than 1% indicates that active exploitation remains unlikely, but the absence of server‑side payment validation increases the overall risk. The CVSS score of 7.5 represents high severity, and the vulnerability is not yet listed in CISA’s KEV catalog. It is inferred that an attacker can still use the public booking endpoint to manipulate payment totals, as no protection is enforced prior to confirming the booking status.
OpenCVE Enrichment