Rox Appointment Booking vulnerability

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.

Published 12 Sep 2026Updated 12 Sep 20261 sources
CVSS 0.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.