{"api_version":"1","generated_at":"2026-09-16T07:45:33+00:00","cve":"CVE-2026-87896","urls":{"html":"https://cve.report/CVE-2026-87896","api":"https://cve.report/api/cve/CVE-2026-87896.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-87896","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87896"},"summary":{"title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST Route","description":"The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:35","updated_at":"2026-09-16 06:16:35"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/658ae610-945a-41cd-ad55-6841fc402035/","name":"https://wpscan.com/vulnerability/658ae610-945a-41cd-ad55-6841fc402035/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87896","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87896","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Rox Appointment Booking","version":"affected 1.2.8 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Pedro Pinho","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Rox Appointment Booking","vendor":"Unknown","versions":[{"lessThan":"1.2.8","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Pedro Pinho"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:17.014Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/658ae610-945a-41cd-ad55-6841fc402035/"}],"source":{"discovery":"EXTERNAL"},"title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST Route","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-87896","datePublished":"2026-09-16T06:00:17.014Z","dateReserved":"2026-09-09T14:59:30.897Z","dateUpdated":"2026-09-16T06:00:17.014Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:35","lastModifiedDate":"2026-09-16 06:16:35","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"87896","Ordinal":"1","Title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disc","CVE":"CVE-2026-87896","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"87896","Ordinal":"1","NoteData":"The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent.","Type":"Description","Title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disc"}]}}}