CVE-2026-91847
Received Received - Intake

Unauthenticated Message Injection in WordPress AI Booking Assistant

Vulnerability report for CVE-2026-91847, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: WPScan

Description

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Online Scheduling and Appointment Booking System WordPress plugin before version 28.2. It allows unauthenticated visitors to access or modify AI booking-assistant conversations without verifying ownership. Attackers can read another user's messages or inject new messages into ongoing conversations.

Detection Guidance

This vulnerability can be detected by checking the version of the Online Scheduling and Appointment Booking System WordPress plugin. If the version is below 28.2, the system is vulnerable. You can check the plugin version via the WordPress admin dashboard or by inspecting the plugin files directly.

Impact Analysis

If you use this WordPress plugin, an attacker could eavesdrop on your private booking conversations or alter them. This could lead to misinformation, data leaks, or disruption of scheduled appointments. The impact is limited to conversation data and does not directly affect other system functions.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data in booking conversations without consent. For HIPAA, it may risk unauthorized access to protected health information if used in healthcare settings. Compliance depends on the data processed and local regulations.

Mitigation Strategies

Update the Online Scheduling and Appointment Booking System WordPress plugin to version 28.2 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91847. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart