Executive brief
The Rox Appointment Booking WordPress plugin allows unauthenticated attackers to create bookings at any price they choose and bypass payment method restrictions. An attacker can book a service worth $100 for just $0.01 or force payment methods that are not enabled on the site. This enables fraud by allowing customers to pay less than the actual service cost or use prohibited payment methods.
Technical details
The vulnerability is a broken access control flaw in the plugin's public REST API booking endpoint. The endpoint accepts the order total and payment method directly from client requests without validating them against server-side configuration. An unauthenticated attacker can POST to /rox-appointment-booking/v1/public/booking with arbitrary values for amount and payment_type; the server does not re-verify the service price or check whether the selected payment method is actually enabled. The only validation present is that the amount cannot be zero. An attacker can thus create confirmed bookings at any positive price and with any payment method, consuming available appointment slots while bypassing payment restrictions. The fix was released in version 1.2.0.
Affected products
- Rox Appointment Booking before 1.2.0
Timeline
- 2026-09-10: disclosed
- 2026-09-12: patched: Fixed in version 1.2.0