CVE-2026-87894

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 06:16

Updated : 2026-09-14 21:10


NVD link : CVE-2026-87894

Mitre link : CVE-2026-87894

CVE.ORG link : CVE-2026-87894


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key