WordPress security by component
Rox Appointment Booking
Rox Appointment Booking (rox-appointment-booking) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
rox-appointment-bookingLatest vulnerability
CVE-2026-87894: Rox Appointment Booking exposes sequential customer records
Rox Appointment Booking from 1.0.9 through versions before 1.2.3 returns booking confirmation details without authorization and addresses each booking with a sequential numeric identifier. An unauthenticated attacker can enumerate IDs to obtain customer names, email addresses, phone numbers, booking details, and payment status. The authoritative export does not name the endpoint or identifier parameter.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-87894
Rox Appointment Booking exposes sequential customer records
Rox Appointment Booking from 1.0.9 through versions before 1.2.3 returns booking confirmation details without authorization and addresses each booking with a sequential numeric identifier. An unauthenticated attacker can enumerate IDs to obtain customer names, email addresses, phone numbers, booking details, and payment status. The authoritative export does not name the endpoint or identifier parameter.
|
1.2.3 |
CVE5.3
NVDPending
|
| Sep 12, 2026 |
CVE-2026-87892
Rox Appointment Booking trusts attacker-supplied prices and payment methods
Rox Appointment Booking before 1.2.0 creates bookings without recalculating the order total or validating the payment method against server-side configuration. An unauthenticated attacker can submit an arbitrary price, create a confirmed booking, and bypass the site's permitted payment methods. The authoritative export does not name the booking endpoint or price and payment fields.
|
1.2.0 |
CVE5.3
NVDPending
|
| Sep 12, 2026 |
CVE-2026-87891
Rox Appointment Booking lets unauthenticated callers rewrite holidays
Rox Appointment Booking before 1.2.0 saves its holiday schedule without a capability or authorization check. An unauthenticated attacker can overwrite unavailable dates, block legitimate bookings, or reopen dates the owner intended to close. The authoritative export does not identify the endpoint, action, date parameter, or storage key.
|
1.2.0 |
CVE6.5
NVDPending
|