Sceawere

Vulnerability Detail

CVE-2026-105198UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Appointment Booking Plugin IDOR Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
8h ago
Vendor
Unknown
Product
Appointment Booking Plugin
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-08T06:16:40.873Z",
  "pubdate": "2026-10-08T06:16:40.873Z",
  "executiveSummary": "The Appointment Booking Plugin for WordPress, in versions prior to 5.7.3, is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability.\nThis flaw resides in the order confirmation summary rendering logic, which fails to perform necessary authorization checks regarding ownership of requested order-item identifiers.\nThe vulnerability allows unauthenticated remote attackers to bypass access controls and perform unauthorized data exfiltration.\nBy manipulating sequential order-item identifiers, an attacker can retrieve sensitive customer information including full names, contact details, and unique order confirmation codes.\nThe risk is classified as critical due to the ease of exploitation, lack of authentication requirements, and the potential for large-scale harvesting of Personal Identifiable Information (PII).\nNo specific user interaction or administrative privileges are required to weaponize this vulnerability, making it an ideal candidate for automated scanning and mass exploitation campaigns.",
  "technicalDetails": "The vulnerability originates from a deficiency in the plugin's authorization enforcement mechanism within the order confirmation retrieval functionality. Specifically, the application logic assumes that knowledge of an order-item identifier is synonymous with authorization to view the associated record.\nThe root cause is an Insecure Direct Object Reference (IDOR) where the application accepts user-supplied input—specifically a sequential order-item ID—as a reference to an object, without validating that the requester has the requisite permissions or established session ownership for that specific object ID.\nAttack flow: An unauthenticated attacker identifies the endpoint responsible for rendering order confirmation summaries. Through observation or predictable pattern analysis, the attacker identifies that the order-item IDs follow a sequential numerical scheme. By iteratively incrementing these IDs within the request parameters (e.g., modifying a GET request parameter), the attacker bypasses the intended scope of the function.\nUpon receiving a request with an incremented ID, the server-side code queries the database for the record associated with that identifier. Because the backend function lacks a check to compare the requester's session or authentication token against the database record's owner field, it proceeds to render the full confirmation page.\nThe resulting HTTP response contains sensitive PII, including the client's full name, telephone number, email address, and the specific appointment confirmation code. This information is rendered directly to the attacker's browser without any access control gatekeeping.\nImpact: This vulnerability facilitates large-scale automated data scraping. An attacker can write a simple script to cycle through IDs, enabling the bulk exfiltration of the entire customer database. This poses significant privacy risks, potential GDPR/CCPA compliance violations, and provides attackers with social engineering material for subsequent, more sophisticated phishing or fraud attacks. The failure to implement server-side authorization at the object level constitutes a critical security design flaw within the plugin's data access layer."
}
CVE-2026-105198: Appointment Booking Plugin IDOR Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere