Executive brief
The Rox Appointment Booking WordPress plugin is a tool that allows businesses to manage appointment reservations and services. Before version 1.2.8, the plugin failed to verify user permissions on certain endpoints, allowing anyone on the internet to view internal notes and sensitive information that should be private, including service details and booking categories.
Technical details
The vulnerability is an authorization bypass (CWE-200) affecting the plugin's REST API endpoints for service and category records. The vulnerable endpoints lack authentication and authorization checks, allowing unauthenticated attackers to directly query and retrieve sensitive internal notes associated with booking services and categories. The attack requires only network access to the WordPress installation; no special preconditions or user interaction is needed. An attacker can read private internal notes that were intended to be viewable only by authenticated administrators. The vulnerability is patched in version 1.2.8.
Affected products
- Rox Appointment Booking before 1.2.8
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in version 1.2.8