Impact
The Rox Appointment Booking plugin for WordPress versions 1.0.9 through 1.2.2 contains a missing authorization check on the booking confirmation endpoint. Each booking is addressed by a sequential numeric identifier, which allows an attacker with no authentication to request any booking ID and receive the customer’s name, email, phone number, booking details and payment status. This secure Direct Object References vulnerability and results in sensitive customer data being disclosed to unauthenticated users.
Affected Systems
WordPress sites that have the Rox Appointment Booking plugin installed in any version from 1.0.9 up to but not including 1.2.3.
Risk and Exploitability
The flaw relies solely on the absence of access‑control logic; an attacker only needs to guess or systematically iterate through booking identifiers to expose data. The likely attack vectorSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation. Nonetheless, the exposure of customer PII can have serious confidentiality implications if accessed by a determined attacker.
OpenCVE Enrichment