CVE-2025-68569

8.8

codepeople · WP Time Slots Booking Form

A missing authorization vulnerability in the WP Time Slots Booking Form plugin allows authenticated users to exploit improperly configured access control settings.

Executive summary

A missing authorization vulnerability in the codepeople WP Time Slots Booking Form plugin poses a significant risk to data confidentiality by allowing unauthorized access to restricted information.

Vulnerability

The plugin suffers from a missing authorization flaw (CWE-862) due to incorrectly configured access control security levels, which can be triggered by an authenticated user with low privileges.

Business impact

Successful exploitation of this vulnerability allows an authenticated attacker to access sensitive information that should otherwise be restricted. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to unauthorized data exposure and potential compliance violations within the affected WordPress environment.

Remediation

Immediate Action: Monitor the plugin developer's official channels for the release of a security patch and update the plugin to the latest version as soon as it becomes available.

Proactive Monitoring: Review web server and WordPress application logs for suspicious access patterns or unauthorized attempts to reach booking form administrative endpoints.

Compensating Controls: If a patch is not immediately available, consider restricting access to the administrative dashboard or implementing a Web Application Firewall (WAF) rule to block requests to the vulnerable plugin endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a high risk to organizational data security due to the potential for unauthorized information disclosure. Administrators should prioritize monitoring for vendor updates and apply the necessary patches immediately upon release to ensure the integrity of the booking system.

More codepeople CVEs

Sources

Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.