Description
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.
Published: 2026-09-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Modification of Booking Availability
Action: Immediate Patch
AI Analysis

Impact

The Rox Appointment Booking WordPress plugin fails to enforce a capability or authentication check when a holiday schedule is saved. This flaw permits any unauthenticated user to submit a request to the plugin’s REST endpoint and overwrite the dates that the booking system marks as unavailable. By manipulating these dates an attacker can block legitimate appointments or create openings that the site operator intended to keep closed, directly disrupting business operations and eroding customer trust.

Affected Systems

Any WordPress site that has installed Rox Appointment Booking version 1.1.x or earlier is affected. The vulnerability applies to all installations that use the default REST endpoint for holiday schedule management; it is independent of other site configuration or security settings.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score is reported as less than 1%. Nevertheless the absence of authentication makes the exploitation path trivial: a single unauthenticated HTTP request to the REST endpoint can alter the schedule. Because the manipulation can have significant operational impact on the booking system and the vulnerability is already known, the overall risk is considered high despite the low EPSS value. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 18:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Rox Appointment Booking to version 1.2.0 or later. This removes the lack of capability and authentication checks when saving holiday schedules.
  • If an upgrade is not immediately possible, protect the plugin’s holiday schedule REST endpoint with a web‑application firewall rule that allows only authenticated users to send POST requests. This orthogonal restriction blocks unauthenticated modification of the schedule.
  • As a last resort, temporarily disable or remove the holiday schedule feature in the plugin configuration until a patch or access control measure can be applied.

Generated by OpenCVE AI on September 15, 2026 at 18:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.
Title Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:29:25.825Z

Reserved: 2026-09-09T14:54:38.167Z

Link: CVE-2026-87891

cve-icon Vulnrichment

Updated: 2026-09-12T15:15:51.779Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:28.003

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-87891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses