CyberRota Analysis
AI-GeneratedThe Rox Appointment Booking plugin for WordPress prior to version 1.2.0 is vulnerable due to a lack of capability and authorization checks when saving holiday schedules. This flaw allows unauthenticated attackers to manipulate the booking system by overwriting unavailable dates, potentially disrupting legitimate bookings and mismanaging site availability. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.