Description
The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to access private internal notes attached to booking services and categories through specific REST routes in the Rox Appointment Booking WordPress plugin. Because no authorization check is performed on these endpoints, an attacker can read sensitive information that should be restricted to authorized users, potentially exposing business logic, schedules, or other confidential data. The loss of confidentiality can undermine trust and operational integrity.

Affected Systems

Sites running the Rox Appointment Booking plugin version 1.2.7 or earlier are affected. Any WordPress installation that has the plugin before version 1.2.8 deployed may expose internal notes via the service and category REST routes. All hosting environments for WordPress with this plugin are potentially impacted, regardless of operating system or web server.

Risk and Exploitability

The attack vector is a remote HTTP request to the vulnerable REST endpoints, requiring no authentication. The CVSS score is not disclosed, but the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the exposure of internal notes presents a moderate risk, as the data exposed could contain sensitive operational information.

Generated by OpenCVE AI on September 16, 2026 at 16:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Rox Appointment Booking plugin to version 1.2.8 or later, which implements proper authorization checks on the affected endpoints.
  • If an immediate update is not possible, restrict access to the service and category REST endpoints by configuring a web‑application firewall or WordPress capability settings to block unauthenticated requests.
  • Review existing internal notes for any sensitive information that may have been exposed, and delete or secure any data that should not be publicly accessible.

Generated by OpenCVE AI on September 16, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.
Title Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST Routes
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-16T06:00:17.191Z

Reserved: 2026-09-09T15:00:27.568Z

Link: CVE-2026-87907

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:35.520

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-87907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:30:08Z

Weaknesses