The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-12 06:16
Updated : 2026-09-14 21:10
NVD link : CVE-2026-87894
Mitre link : CVE-2026-87894
CVE.ORG link : CVE-2026-87894
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
