Impact
The Rox Appointment Booking WordPress plugin fails to enforce a capability or authentication check when a holiday schedule is saved. This flaw permits any unauthenticated user to submit a request to the plugin’s REST endpoint and overwrite the dates that the booking system marks as unavailable. By manipulating these dates an attacker can block legitimate appointments or create openings that the site operator intended to keep closed, directly disrupting business operations and eroding customer trust.
Affected Systems
Any WordPress site that has installed Rox Appointment Booking version 1.1.x or earlier is affected. The vulnerability applies to all installations that use the default REST endpoint for holiday schedule management; it is independent of other site configuration or security settings.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is reported as less than 1%. Nevertheless the absence of authentication makes the exploitation path trivial: a single unauthenticated HTTP request to the REST endpoint can alter the schedule. Because the manipulation can have significant operational impact on the booking system and the vulnerability is already known, the overall risk is considered high despite the low EPSS value. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment