Impact
The Booking for Appointments and Events Calendar WordPress plugin, which powers the Amelia booking module, fails to verify that a user possesses the proper capability before changing an appointment’s status. This flaw is a CWE-863 Lack of Security Checks. As a result, any customer who has an appointment can arbitrarily modify the status, including approving their own pending bookings or overriding the status set by other customers on shared appointments.
Affected Systems
The vulnerability affects Booking for Appointments and Events Calendar WordPress plugin versions 1.2.32 through 2.4.8, the last release before the fix in 2.4.9. It applies to any WordPress site that installs this plugin, independent of theme or other plugins, because the flaw resides in the plugin’s core.
Risk and Exploitability
The likely attack vector is through the normal WordPress front‑end or a REST endpoint that accepts status change requests, with a low barrier to entry. The vulnerability has a CVSS score of 2.7 and an EPSS score of <1%, and it is not listed in CISA KEV. Because the flaw allows arbitrary status changes, the risk is modest but any unauthorized status change could allow a customer to bypass administrative approval and potentially create service pickups or billing.
OpenCVE Enrichment