CVE-2025-68569
8.8codepeople · WP Time Slots Booking Form
A missing authorization vulnerability in the WP Time Slots Booking Form plugin allows authenticated users to exploit improperly configured access control settings.
Executive summary
A missing authorization vulnerability in the codepeople WP Time Slots Booking Form plugin poses a significant risk to data confidentiality by allowing unauthorized access to restricted information.
Vulnerability
The plugin suffers from a missing authorization flaw (CWE-862) due to incorrectly configured access control security levels, which can be triggered by an authenticated user with low privileges.
Business impact
Successful exploitation of this vulnerability allows an authenticated attacker to access sensitive information that should otherwise be restricted. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to unauthorized data exposure and potential compliance violations within the affected WordPress environment.
Remediation
Immediate Action: Monitor the plugin developer's official channels for the release of a security patch and update the plugin to the latest version as soon as it becomes available.
Proactive Monitoring: Review web server and WordPress application logs for suspicious access patterns or unauthorized attempts to reach booking form administrative endpoints.
Compensating Controls: If a patch is not immediately available, consider restricting access to the administrative dashboard or implementing a Web Application Firewall (WAF) rule to block requests to the vulnerable plugin endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a high risk to organizational data security due to the potential for unauthorized information disclosure. Administrators should prioritize monitoring for vendor updates and apply the necessary patches immediately upon release to ensure the integrity of the booking system.
More codepeople CVEs
Sources
Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.