Impact
The vulnerability allows an unauthenticated attacker to access private internal notes attached to booking services and categories through specific REST routes in the Rox Appointment Booking WordPress plugin. Because no authorization check is performed on these endpoints, an attacker can read sensitive information that should be restricted to authorized users, potentially exposing business logic, schedules, or other confidential data. The loss of confidentiality can undermine trust and operational integrity.
Affected Systems
Sites running the Rox Appointment Booking plugin version 1.2.7 or earlier are affected. Any WordPress installation that has the plugin before version 1.2.8 deployed may expose internal notes via the service and category REST routes. All hosting environments for WordPress with this plugin are potentially impacted, regardless of operating system or web server.
Risk and Exploitability
The attack vector is a remote HTTP request to the vulnerable REST endpoints, requiring no authentication. The CVSS score is not disclosed, but the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the exposure of internal notes presents a moderate risk, as the data exposed could contain sensitive operational information.
OpenCVE Enrichment