CVE-2026-87892
Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.
| Vendor | unknown |
| Product | rox appointment booking |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown rox appointment booking
Be the first to know when new medium vulnerabilities affecting unknown rox appointment booking are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Rox Appointment Booking
0 < 1.2.0
References
Credits
Morato Antoine WPScan