CyberRota Analysis
AI-GeneratedThe Appointment Booking Plugin for WordPress versions prior to 5.6.8 is vulnerable, allowing unauthenticated users to manipulate booking fields, including the approval status, through the public booking funnel. This flaw can lead to unauthorized bypassing of the site's booking approval workflow, potentially compromising the integrity of booking processes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.