What the vulnerability does
01Description
Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.
Explanation of Vulnerability in Simple Terms
The Appointment Hour Booking WordPress plugin through version 1.3.71 does not properly check user permissions before allowing modifications to appointment data. A logged-in user with low privileges can alter appointments they should not have access to. The vulnerability requires an active WordPress account but no special role or capability.
What an attacker can do
Modify appointment records belonging to other users or the site.
Potential impact on your site
Appointment data integrity is at risk; users' bookings can be altered by other logged-in users.
Conditions required to exploit
Attacker must have a valid WordPress user account with low-level privileges.
Key dates
External resources
Related vulnerabilities