{"api_version":"1","generated_at":"2026-09-16T07:44:25+00:00","cve":"CVE-2026-87907","urls":{"html":"https://cve.report/CVE-2026-87907","api":"https://cve.report/api/cve/CVE-2026-87907.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-87907","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87907"},"summary":{"title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST Routes","description":"The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:35","updated_at":"2026-09-16 06:16:35"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/60f70070-f785-43a2-be51-c01e64fb1821/","name":"https://wpscan.com/vulnerability/60f70070-f785-43a2-be51-c01e64fb1821/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87907","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87907","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Rox Appointment Booking","version":"affected 1.2.8 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Farid Narimanov","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Rox Appointment Booking","vendor":"Unknown","versions":[{"lessThan":"1.2.8","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Farid Narimanov"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:17.191Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/60f70070-f785-43a2-be51-c01e64fb1821/"}],"source":{"discovery":"EXTERNAL"},"title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST Routes","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-87907","datePublished":"2026-09-16T06:00:17.191Z","dateReserved":"2026-09-09T15:00:27.568Z","dateUpdated":"2026-09-16T06:00:17.191Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:35","lastModifiedDate":"2026-09-16 06:16:35","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"87907","Ordinal":"1","Title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes","CVE":"CVE-2026-87907","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"87907","Ordinal":"1","NoteData":"The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.","Type":"Description","Title":"Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes"}]}}}