Impact
The vulnerability resides in the Bookit — Booking & Appointment Calendar WordPress plugin versions earlier than 2.6.0.5, where one of the appointment‑deletion functions fails to perform a capability check. This omission allows a user who has the plugin’s low‑privileged Staff role to delete any appointment stored in the system. The deletion can remove scheduled events, disrupt client bookings, and erase billing or history data, thereby compromising the integrity of the booking database. The weakness is an authorization bypass identified as CWE‑862.
Affected Systems
WordPress sites that have the Bookit plugin (Booking & Appointment Calendar) installed with a version prior to 2.6.0.5. The vulnerability is present in every installation that does not upgrade to the patched release, regardless of other security plugins or hardening settings.
Risk and Exploitability
The CVSS base score is 2.7, reflecting a low confidentiality and integrity impact with no availability effect. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Exploitation would occur via the WordPress admin interface or any exposed REST endpoint that triggers the deletion process; an attacker only needs access to a Staff‑level user account. No additional secrets or privileges are required.
OpenCVE Enrichment