Engagements  /  PSY-WEB-0318

A booking plugin that exposed the appointment book

A dental group’s website was a few pages and a booking plugin. The plugin was the problem.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Sector
Healthcare and health tech
Engagement
Web app pentest
Frameworks
OWASP Top 10:2025, CIS Controls v8.1 IG1, provincial health-privacy law
Duration
6 test days

A multi-location dental group.

Seven clinics shared one WordPress site with an online booking plugin and an intake form for new patients. The site had been built by one agency and maintained by another.

The practice manager asked for a test after a patient mentioned seeing someone else’s name in a confirmation email.

What we did

Small site, real patient data.

Start with the complaint

The confirmation email linked to a booking page by a short numeric ID. Incrementing it showed other patients’ appointments, names and reasons for visit.

Check the intake path

New-patient forms were stored as uploads in a public folder with guessable filenames, and indexed by a search engine.

Fix the basics underneath

We used CIS Controls v8.1 IG1 as a checklist for the site’s hosting and admin accounts, which turned up six administrators who no longer worked there.

What we found

Patient data, one ID at a time.

SeverityFindingMaps toStatus at retest
CriticalBooking confirmation pages accessible by sequential ID without authentication.A01:2025 · CWE-639Closed
HighIntake-form uploads publicly accessible and search-indexed.A01:2025 · A02:2025Closed
MediumBooking plugin two major versions behind, with a published vulnerability.A03:2025 · CIS 7.4Closed
MediumSix former staff with active WordPress administrator accounts.CIS 5.3 · 6.2Closed
MediumNo MFA on WordPress or hosting control panel.CIS 6.3 · A07:2025Closed

What changed.

The plugin vendor fixed the ID exposure after coordinated disclosure; in the meantime the group replaced the confirmation link with a signed, expiring token. The exposed uploads were removed and de-indexed.

The group took legal advice on notification obligations, using the scope and timeline in our report as the factual record.

Next engagement

Want this for your application?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.