Junglewise Threat Intelligence

CVE-2026-87894: Rox Appointment Booking authorization bypass in REST endpoint

CVE-2026-87894 · Severity: medium · CVSS 5.3 · Published 2026-09-12

Technologies: Rox Appointment Booking.

Executive brief

The Rox Appointment Booking WordPress plugin before version 1.2.3 contains a vulnerability that allows unauthenticated attackers to access sensitive customer information without any credentials. By guessing sequential booking IDs, attackers can retrieve customer names, emails, phone numbers, booking details, and payment status. This exposes private customer data and could enable fraud, phishing, or other misuse of personal information.

Technical details

The plugin fails to implement authorization checks on the booking-confirmation REST API endpoint (/wp-json/rox-apartment-booking/v1/public/booking/confirmation/{id}), with a permission callback that always returns true. Bookings are identified by sequential auto-incrementing numeric IDs, enabling trivial enumeration. An unauthenticated attacker with network access to the WordPress site can enumerate the entire customer database by iterating through booking IDs, retrieving full PII including name, email, phone, service details, and payment status. The vulnerability is classified as Insecure Direct Object Reference (IDOR) and requires no authentication, user interaction, or special preconditions beyond at least one booking existing in the system. Patches are available in version 1.2.3 and later.

Affected products

  • Rox Appointment Booking 1.0.9 to 1.2.2

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: patched: Fixed in version 1.2.3

References