CyberRota Analysis
AI-GeneratedThe bookingpress-appointment-booking-pro plugin for WordPress versions prior to 5.7.3 is vulnerable due to improper REST permission handling, enabling unauthenticated attackers to access customer booking data and alter other users' bookings. This high-severity vulnerability poses a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.