Impact
The vulnerability allows an unauthenticated visitor to read messages from another user's AI booking‑assistant conversation and to inject messages into an in‑progress conversation. This provides the attacker with confidential user information and the ability to alter the intended conversation flow, potentially leading to misinformation or user manipulation.
Affected Systems
The affected product is the Online Scheduling and Appointment Booking System WordPress plugin, versions prior to 28.2. The plugin does not enforce ownership checks on its AI conversation actions, enabling the flaw across all earlier releases of this plugin. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score is not specified, but the attack vector is unauthenticated and remote, relying only on web interaction. EPSS data is unavailable, so the absolute likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is an IDOR that grants both data read and modification, it poses a serious confidentiality and integrity risk and could be exploited by any unauthenticated web user. No explicit exploit code is yet public, but the path is straightforward: send a request to the conversation endpoint with another user’s conversation ID and retrieve or inject messages.
OpenCVE Enrichment