Executive brief
The Rox Appointment Booking WordPress plugin allows unauthenticated users to modify the holiday schedule that controls booking availability. An attacker can block all bookings by marking every future date as unavailable, or re-open dates the site owner intended to keep closed, directly impacting revenue and customer experience.
Technical details
This is an authorization bypass vulnerability in the plugin's REST API endpoint for saving holiday schedules. The vulnerable REST route uses a permission callback that always returns true, requiring no authentication, nonce validation, or capability checks. Attackers can send unauthenticated POST requests to /wp-json/rox-appointment-booking/v1/menueapi/holiday/save with arbitrary holiday data to completely overwrite the stored holiday option. The booking availability logic then enforces the attacker-supplied dates, allowing denial of service (blocking all bookings) or enabling unauthorized access (opening dates marked closed). The vulnerability is fixed in version 1.2.0.
Affected products
- Rox Appointment Booking before 1.2.0
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Version 1.2.0 fixes the vulnerability