Impact
The vulnerability allows an unauthenticated visitor to read messages from another user's AI booking‑assistant conversation and to inject messages into an in‑progress conversation. This provides the attacker with confidential user information and the ability to alter the intended conversation flow, potentially leading to misinformation or user manipulation.
Affected Systems
The affected product is the Online Scheduling and Appointment Booking System WordPress plugin, versions prior to 28.2. The plugin does not enforce ownership checks on its AI conversation actions, enabling the flaw across all earlier releases of this plugin. No other vendors or products are listed in the CNA data.
Risk and Exploitability
High‑level risk assessment: The flaw is an unauthenticated IDOR that permits reading and injecting AI assistant conversation content. The CVSS score of 4.8 classifies it as low severity. The EPSS score is below 1%, indicating a low predicted likelihood of mass exploitation. The vulnerability is not listed in the CISA KEV catalog. Because any unauthenticated web user can send a request to the conversation endpoint with a target user’s conversation ID, they can retrieve or alter messages in real time. The attack requires no special credentials or analytical skills; it merely involves crafting a suitable HTTP request. While the impact does not allow full system compromise, it leaks potentially private AI conversation data and could disrupt legitimate booking interactions.
OpenCVE Enrichment