CyberRota Analysis
AI-GeneratedThe Rox Appointment Booking plugin for WordPress prior to version 1.2.3 is vulnerable due to a lack of authorization checks on its endpoint, enabling unauthenticated attackers to access sensitive booking information, including customer names, emails, phone numbers, and payment statuses. This vulnerability poses a significant risk to customer privacy and data security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.