UNKNOWN NVD

CVE-2026-87907

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category re

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.

References

Published: 2026-09-16 · Source: NVD · Feed updated: 2026-09-16
This unknown severity vulnerability was published on 2026-09-16 via NVD.
vulnfeed aggregates 14123 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.