Beveiligingsadvies

CVE-2026-87891

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-12 06:00:12
Laatst bijgewerkt 2026-09-12 15:29:25
Toegewezen door WPScan
CVSS-score 6.5
Status PUBLISHED

Beschrijving

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.