Description
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated price manipulation and payment method bypass
Action: Patch
AI Analysis

Impact

The Rox Appointment Booking WordPress plugin before version 1.2.0 fails to verify the order total or the selected payment method against its own server‑side pricing logic when creating a booking. This omission allows an unauthenticated attacker to submit reservations with an arbitrary price and to select payment methods that the site has configured to be unavailable, resulting in fraudulent confirmed bookings and potential financial loss for the site owner.

Affected Systems

Any WordPress site that has installed the Rox Appointment Booking plugin with a version earlier than 1.2.0 is affected; the plugin does not list a traditional vendor name.

Risk and Exploitability

The flaw does not require authentication and can be triggered via the normal booking API calls, making it easily exploitable by any user who can access the site. The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the lack of server‑side verification poses a tangible risk of financial loss and abuse of configured payment methods.

Generated by OpenCVE AI on September 15, 2026 at 18:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Rox Appointment Booking plugin to version 1.2.0 to enforce server‑side verification of booking totals and payment methods.
  • If an immediate upgrade is not possible, disable unauthenticated booking creation or require user authentication before booking can be submitted.
  • Implement server‑side checks to validate the price improper access control flaw (CWE‑284).
  • Regularly audit booking records for anomalies in pricing or payment method usage to detect potential abuse.

Generated by OpenCVE AI on September 15, 2026 at 18:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.
Title Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:29:10.292Z

Reserved: 2026-09-09T14:56:23.500Z

Link: CVE-2026-87892

cve-icon Vulnrichment

Updated: 2026-09-12T15:15:32.245Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:28.110

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-87892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses