Booktics – Appointment Booking Calendar for Service Businesses <= 1.0.27 - Authenticated (Subscriber+) Missing Authorization to Appointment Data and Security Token Exposure via Calendar Appointments Route

Medium 5.4 CWE-862Fixed in 1.0.28
ID
WPSEC-2026-0587
Plugin
Booktics – Appointment Booking Calendar for Service Businesses (booktics)
Affected
all versions before 1.0.28
Remediation
Update to 1.0.28 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Booktics – Appointment Booking Calendar for Service Businesses on WPSec AttackSurface
Fix released
Published

Description

The Booktics – Appointment Booking Calendar for Service Businesses plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.0.27 due to a missing ownership check on the calendar appointments REST route, which is available to any logged-in user and returns every appointment in the requested date range, including the customer's name, email address and phone number, the appointment notes, and the per-appointment security token that authorizes cancelling and rescheduling. This makes it possible for authenticated attackers, with subscriber-level access and above, to view other customers' appointment details and, on sites that allow customers to cancel or reschedule their bookings, to cancel or reschedule other customers' appointments.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0