CyberRota Analysis
AI-GeneratedThe Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.6 is vulnerable due to a lack of verification for authenticated employees accessing appointment details, enabling unauthorized access to sensitive customer information. This flaw poses a significant risk of personal data exposure, making it critical for organizations using this plugin to prioritize updates to mitigate potential data breaches. WordPress site administrators and those managing appointment-related functionalities should address this vulnerability promptly.
Original NVD Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.