VYPR

Rox Appointment Booking

by WordPress

CVEs (3)

  • CVE-2026-87894Sep 12, 2026
    risk 0.00cvss epss

    The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any…

  • CVE-2026-87892Sep 12, 2026
    risk 0.00cvss epss

    The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to…

  • CVE-2026-87891Sep 12, 2026
    risk 0.00cvss epss

    The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate…