Impact
Users of the Rox Appointment Booking plugin prior to version 1.2.8 can be exposed to a significant privacy breach. The plugin's endpoint that delivers agent (staff) records performs no authorization check, which means any internet-connected user can retrieve email addresses, phone numbers, private notes, and WordPress account names for all staff members. The flaw allows attackers to obtain private personal information and potentially use it for phishing or other malicious purposes.
Affected Systems
Affected systems include any WordPress installation that has the Rox Appointment Booking plugin installed and not upgraded to 1.2.8 or later. The vulnerability is present in all earlier releases regardless of configuration, because the code path lacks an access control guard. The exact affected version range is from the plugin's initial release up through 1.2.7.
Risk and Exploitability
The risk is high: the CVSS calculations are not provided, but the EPSS score is below 1% indicating current exploitation probability is low; however the privacy impact is considerable. Attackers do not need privileged access and only need to know the public URIs used by the plugin's REST API. The vulnerability is not listed in the CISA KEV catalog, meaning no known broad exploitation has been reported, but the weakness remains exploitable until patched.
OpenCVE Enrichment