CVE-2025-68575

8.8

Wappointment team · Wappointment

A missing authorization vulnerability in the Wappointment plugin allows unauthenticated attackers to exploit incorrectly configured access control security levels.

Executive summary

The Wappointment plugin for WordPress is vulnerable to a missing authorization flaw that permits unauthenticated attackers to perform unauthorized actions due to improper access control.

Vulnerability

This vulnerability is classified as a missing authorization flaw (CWE-862). It allows an unauthenticated attacker to bypass intended access control restrictions, potentially modifying plugin settings or data without requiring valid credentials.

Business impact

The exploitability of this flaw by unauthenticated users poses a significant risk to the integrity of data managed by the Wappointment plugin. With a CVSS score of 8.8, this vulnerability is categorized as High, as it could lead to unauthorized administrative actions that disrupt business operations or compromise sensitive booking information. Organizations relying on this plugin for scheduling may face reputational damage and data inconsistencies if the access control is successfully bypassed.

Remediation

Immediate Action: As no specific patch version is currently confirmed, administrators should immediately disable or remove the Wappointment plugin until an official security update is released by the vendor.

Proactive Monitoring: Review web server and WordPress access logs for anomalous requests directed at plugin-specific endpoints, particularly those originating from unauthorized or unknown IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns targeting the plugin's REST API or administrative endpoints to mitigate the risk of exploitation.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the High severity rating and the lack of a verified patch, the risk to the environment is substantial. Security teams must prioritize the immediate deactivation of the Wappointment plugin to prevent unauthorized access. Monitor vendor communications closely for the release of a secure version, and perform a thorough audit of any data modified through the plugin before resuming operations.

Sources

Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.