Junglewise Threat Intelligence

CVE-2026-87896: Rox Appointment Booking unauthorized staff data disclosure

CVE-2026-87896 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Technologies: Rox Appointment Booking.

Executive brief

Rox Appointment Booking is a WordPress plugin for managing appointment scheduling and staff bookings. The plugin exposes sensitive staff information—including email addresses, phone numbers, private notes, and linked WordPress account names—to anyone without requiring authentication. An attacker can easily access this data via an unprotected API endpoint, compromising staff privacy and potentially enabling targeted attacks.

Technical details

The Rox Appointment Booking plugin before version 1.2.8 fails to implement authorization checks on a REST API endpoint that returns booking agent (staff) records. The vulnerability is a missing access control issue (CWE-200) affecting the endpoint that serves staff data. An unauthenticated attacker can send a network request to this endpoint to retrieve staff email addresses, phone numbers, private internal notes, and linked WordPress account usernames without any credentials or user interaction. The vulnerability is fixed in version 1.2.8 or later.

Affected products

  • Rox Appointment Booking before 1.2.8

Timeline

  • 2026-09-14: disclosed
  • 2026-09-16: advisory
  • 2026-09-16: patched: Fixed in version 1.2.8

References