---
id: CVE-2026-86841
title: >-
  The Online Scheduling and Appointment Booking System  WordPress plugin before
  28.3 does not prevent deserialization of untrusted input and does not
  correctly restrict a privileged maintenance feature to administrators,
  allowing users gra…
summary: >-
  The Online Scheduling and Appointment Booking System  WordPress plugin before
  28.3 does not prevent deserialization of untrusted input and does not
  correctly restrict a privileged maintenance feature to administrators,
  allowing users gra…
severity: none
cwe:
  - CWE-502
product: Online Scheduling and Appointment Booking System
affected:
  - online_scheduling_and_appointment_booking_system >= 23.2 < 28.3
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T06:17:17.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86841'
references:
  - url: 'https://wpscan.com/vulnerability/2150717e-7564-4b29-b2e7-362dd3b480c3/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T06:43:46.830Z'
---

## Overview

The Online Scheduling and Appointment Booking System  WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
