CVE-2026-87894
Received Received - Intake

Unauthenticated Information Disclosure in Rox Appointment Booking WordPress Plugin

Vulnerability report for CVE-2026-87894, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rox_appointment_booking rox_appointment_booking From 1.0.9 (inc) to 1.2.2 (inc)
rox appointment_booking to 1.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the Rox Appointment Booking WordPress plugin versions 1.0.9 to 1.2.2. It allows unauthenticated attackers to access sensitive customer personally identifiable information (PII) by exploiting a lack of authorization checks on an endpoint that retrieves booking confirmation details. Attackers can enumerate sequential numeric IDs to retrieve customer names, emails, phone numbers, booking details, and payment status.

Detection Guidance

To detect this vulnerability, check if the Rox Appointment Booking plugin version is between 1.0.9 and 1.2.2. Test the endpoint by accessing sequential numeric IDs to see if sensitive customer data is exposed without authentication.

Impact Analysis

If you are a user of the Rox Appointment Booking plugin versions 1.0.9 to 1.2.2, attackers could access your personal data, including name, email, phone number, booking details, and payment status. This could lead to identity theft, fraud, or other malicious activities. Website owners should update to version 1.2.3 or later to mitigate this risk.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and other privacy regulations due to unauthorized access to personal data. GDPR requires protecting personal data, and a breach like this could result in fines or legal consequences. HIPAA may also be affected if health-related booking details are exposed.

Mitigation Strategies

Immediately update the Rox Appointment Booking plugin to version 1.2.3 or later to fix the vulnerability. If updating is not possible, consider disabling the plugin until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87894. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart