Start with the complaint
The confirmation email linked to a booking page by a short numeric ID. Incrementing it showed other patients’ appointments, names and reasons for visit.
Penspy is an independent security firm, testing web applications and auditing against the frameworks you answer to.
A dental group’s website was a few pages and a booking plugin. The plugin was the problem.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
A multi-location dental group.
Seven clinics shared one WordPress site with an online booking plugin and an intake form for new patients. The site had been built by one agency and maintained by another.
The practice manager asked for a test after a patient mentioned seeing someone else’s name in a confirmation email.
The confirmation email linked to a booking page by a short numeric ID. Incrementing it showed other patients’ appointments, names and reasons for visit.
New-patient forms were stored as uploads in a public folder with guessable filenames, and indexed by a search engine.
We used CIS Controls v8.1 IG1 as a checklist for the site’s hosting and admin accounts, which turned up six administrators who no longer worked there.
| Severity | Finding | Maps to | Status at retest |
|---|---|---|---|
| Critical | Booking confirmation pages accessible by sequential ID without authentication. | A01:2025 · CWE-639 | Closed |
| High | Intake-form uploads publicly accessible and search-indexed. | A01:2025 · A02:2025 | Closed |
| Medium | Booking plugin two major versions behind, with a published vulnerability. | A03:2025 · CIS 7.4 | Closed |
| Medium | Six former staff with active WordPress administrator accounts. | CIS 5.3 · 6.2 | Closed |
| Medium | No MFA on WordPress or hosting control panel. | CIS 6.3 · A07:2025 | Closed |
What changed.
The plugin vendor fixed the ID exposure after coordinated disclosure; in the meantime the group replaced the confirmation link with a signed, expiring token. The exposed uploads were removed and de-indexed.
The group took legal advice on notification obligations, using the scope and timeline in our report as the factual record.
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.