CVE-2026-87907

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-16 06:16

Updated : 2026-09-16 20:25


NVD link : CVE-2026-87907

Mitre link : CVE-2026-87907

CVE.ORG link : CVE-2026-87907


JSON object : View

Products Affected

No product.

CWE

No CWE.