Impact
The Easy Appointments WordPress plugin prior to version 4.0.2.2 fails to perform an ownership or authorization check on its appointment‑reservation endpoint. An attacker who can send an unauthenticated HTTP request can supply any appointment identifier and overwrite the corresponding appointment data. The flaw also permits the deletion of appointments through a follow‑on cleanup action. The weakness is an IDOR flaw, documented as CWE-639, and consequently allows an attacker to arbitrarily modify or delete appointments, which can lead to scheduling disruption and data loss.
Affected Systems
The vulnerable product is the Easy Appointments WordPress plugin, labeled generically as "Easy Appointments". Based on the description, it is inferred that all releases from version 4.0 up to 4.0.2.1 are affected; the issue is fixed in 4.0.2.2 and later.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating a moderate severity and a low exploitability reflected by an EPSS score of less than 1%. It is not listed in the CISA KEV catalog, suggesting no publicly available exploitation. Nevertheless, the flaw is exploitable by anyone with internet access to the vulnerable WordPress site, as it does not require authentication. The attack path involves submitting a crafted request to the appointment‑reservation endpoint with a chosen ID, enabling unauthorized appointment manipulation. While the probability of exploitation is currently low, the potential impact on business continuity and data integrity warrants prompt remediation.
OpenCVE Enrichment