{"api_version":"1","generated_at":"2026-09-12T09:55:34+00:00","cve":"CVE-2026-87891","urls":{"html":"https://cve.report/CVE-2026-87891","api":"https://cve.report/api/cve/CVE-2026-87891.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-87891","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87891"},"summary":{"title":"Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API","description":"The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-12 06:16:28","updated_at":"2026-09-12 06:16:28"},"problem_types":["CWE-284 Improper Access Control"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/e7f3b29e-2503-41bb-b15c-3c0ef71a3a00/","name":"https://wpscan.com/vulnerability/e7f3b29e-2503-41bb-b15c-3c0ef71a3a00/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87891","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87891","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Rox Appointment Booking","version":"affected 1.2.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Pedro Pinho","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Rox Appointment Booking","vendor":"Unknown","versions":[{"lessThan":"1.2.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Pedro Pinho"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed."}],"problemTypes":[{"descriptions":[{"description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-12T06:00:12.844Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/e7f3b29e-2503-41bb-b15c-3c0ef71a3a00/"}],"source":{"discovery":"EXTERNAL"},"title":"Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-87891","datePublished":"2026-09-12T06:00:12.844Z","dateReserved":"2026-09-09T14:54:38.167Z","dateUpdated":"2026-09-12T06:00:12.844Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-12 06:16:28","lastModifiedDate":"2026-09-12 06:16:28","problem_types":["CWE-284 Improper Access Control"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"87891","Ordinal":"1","Title":"Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedu","CVE":"CVE-2026-87891","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"87891","Ordinal":"1","NoteData":"The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.","Type":"Description","Title":"Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedu"}]}}}