Impact
The flaw exists in the Appointment Booking Calendar Plugin and Scheduling Plugin prior to version 1.6.3. When a user completes an online PayPal payment, the plugin fails to compare the amount received with the expected price stored server‑side for the booking. An unauthenticated caller can therefore trigger a booking confirmation with a partial or incorrect payment amount, causing the system to mark the appointment as fully paid for a fraction of its true cost. The resulting impact is a direct monetary loss for the service provider and a potential abuse vector for customers who receive services without paying the full negotiated fee.
Affected Systems
Any WordPress installation using the Appointment Booking Calendar Plugin or Scheduling Plugin with a version older than 1.6.3 is affected. The affected products are the unbranded Appointment Booking Calendar Plugin and Scheduling Plugin, widely used within WordPress sites for booking scheduling. No specific vendor name is provided, but the public reference links to a WPScan advisory for the plugin.
Risk and Exploitability
Because the vulnerability is exploitable without authentication and requires only a standard payment initiation on the public booking endpoint, the risk is high. The exploit is straightforward, with no special prerequisites other than access to the booking interface. EPSS data is unavailable, but the lack of any mitigation in the plugin implies a high likelihood of exploitation. The CVSS score is not supplied, but the impact on financial integrity alone would elevate it to a critical rating. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment