Description
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The Rox Appointment Booking plugin for WordPress versions 1.0.9 through 1.2.2 contains a missing authorization check on the booking confirmation endpoint. Each booking is addressed by a sequential numeric identifier, which allows an attacker with no authentication to request any booking ID and receive the customer’s name, email, phone number, booking details and payment status. This secure Direct Object References vulnerability and results in sensitive customer data being disclosed to unauthenticated users.

Affected Systems

WordPress sites that have the Rox Appointment Booking plugin installed in any version from 1.0.9 up to but not including 1.2.3.

Risk and Exploitability

The flaw relies solely on the absence of access‑control logic; an attacker only needs to guess or systematically iterate through booking identifiers to expose data. The likely attack vectorSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation. Nonetheless, the exposure of customer PII can have serious confidentiality implications if accessed by a determined attacker.

Generated by OpenCVE AI on September 15, 2026 at 18:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Rox Appointment Booking plugin to version 1.2.3 or newer, which implements the missing authorization check on the booking confirmation endpoint.
  • If an update is not immediately possible, to require authentication (for example, enforce login or apply IP restrictions) before allowing access to the booking detail URLs.
  • Review the plugin’s source code or documentation to confirm that no additional access‑control gaps remain.

Generated by OpenCVE AI on September 15, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
Title Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:28:54.759Z

Reserved: 2026-09-09T14:58:05.190Z

Link: CVE-2026-87894

cve-icon Vulnrichment

Updated: 2026-09-12T15:15:12.753Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:28.217

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-87894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key