CVE-2026-87891
Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.
| Vendor | unknown |
| Product | rox appointment booking |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown rox appointment booking
Be the first to know when new medium vulnerabilities affecting unknown rox appointment booking are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Rox Appointment Booking
0 < 1.2.0
References
Credits
Pedro Pinho WPScan