Impact
The Bookit – Booking & Appointment Calendar WordPress plugin before version 2.6.0.5 contains a missing authorization check on an appointment‑retrieval endpoint, which enables users who possess a low‑privilege plugin‑defined role to retrieve appointment records for other users. The exposed records include customer names, email addresses, phone numbers and private booking comments, which constitutes a protection‑of‑information violation (CWE‑200). While the vulnerability does not provide remote code execution or a denial‑of‑service vector, it allows unauthorized read access to personal data, presenting a privacy and compliance risk.
Affected Systems
Any WordPress site that installs Bookit – Booking & Appointment Calendar prior to version 2.6.0.5 is vulnerable. The specific product is the plugin itself; no particular sub‑components are singled out beyond the appointment‑retrieval action. Sites using any earlier release, regardless of the number of appointments, are at risk of exposing customer personal data to users with the restricted role.
Risk and Exploitability
The CVSS score of 2.7 indicates a low‑severity information disclosure scenario. The EPSS score is reported as less than 1 %, which suggests a very low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating limited exploitation. The likely attack vector is the same internal, authenticated route used by the plugin to fetch appointment data; an attacker only needs to be logged in and possess the vulnerable role to trigger the flaw. The missing authorization check means no additional privileges or technical steps are required beyond normal plugin usage.
OpenCVE Enrichment