Impact
The Rox Appointment Booking WordPress plugin before version 1.2.0 fails to verify the order total or the selected payment method against its own server‑side pricing logic when creating a booking. This omission allows an unauthenticated attacker to submit reservations with an arbitrary price and to select payment methods that the site has configured to be unavailable, resulting in fraudulent confirmed bookings and potential financial loss for the site owner.
Affected Systems
Any WordPress site that has installed the Rox Appointment Booking plugin with a version earlier than 1.2.0 is affected; the plugin does not list a traditional vendor name.
Risk and Exploitability
The flaw does not require authentication and can be triggered via the normal booking API calls, making it easily exploitable by any user who can access the site. The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the lack of server‑side verification poses a tangible risk of financial loss and abuse of configured payment methods.
OpenCVE Enrichment