Impact
Users of the Rox Appointment Booking plugin prior to version 1.2.8 can be exposed to a significant privacy breach. The plugin's endpoint that delivers agent (staff) records performs no authorization check, which means any internet-connected user can retrieve email addresses, phone numbers, private notes, and WordPress account names for all staff members. The flaw allows attackers to obtain private personal information and potentially use it for phishing or other malicious purposes.
Affected Systems
Affected systems include any WordPress installation that has the Rox Appointment Booking plugin installed and not upgraded to 1.2.8 or later. The vulnerability is present in all earlier releases regardless of configuration, because the code path lacks an access control guard. The exact affected version range is from the plugin's initial release up through 1.2.7.
Risk and Exploitability
The risk is moderate, reflected by a CVSS score of 5.3, indicating medium severity. The EPSS score of less than 1% indicates a low probability of current exploitation, yet the privacy impact is significant because any internet user can read staff email addresses, phone numbers, private notes, and linked WordPress accounts. Attackers need no privileges and only need to target the plugin's publicly exposed REST API endpoint. The vulnerability is not listed in the CISA KEV catalog, so no large-scale exploitation is known, but the flaw remains present until patched.
OpenCVE Enrichment