Impact
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly limit the data returned by an availability‑check request. An unauthenticated attacker can retrieve appointment details of other customers, including free‑text comments and contact information, exposing personally identifiable information to anyone who can access the endpoint. Versions older than 2.6.0.1 are affected. This vulnerability represents a CWE-200 weakness.
Affected Systems
The affected product is the WordPress plugin Bookit — Booking & Appointment Calendar, in versions earlier than 2.6.0.1. Those releases expose appointment data through the availability‑check endpoint to unauthenticated users.
Risk and Exploitability
The vulnerability requires only an unauthenticated HTTP request to the availability‑check endpoint; no authentication or privileged access is needed. Its CVSS score of 5.3 indicates moderate risk. With an EPSS score of 0.00206 and it not appearing in the CISA KEV catalog, there is no evidence of active exploitation, but the ability to read sensitive appointment details can lead to privacy violations and regulatory non‑compliance. The very low EPSS value implies a low probability of exploitation.
OpenCVE Enrichment