---
id: CVE-2026-87891
title: >-
  The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform
  any capability or authorization check when saving its holiday schedule,
  allowing unauthenticated attackers to overwrite the dates the booking system
  treats as un…
summary: >-
  The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform
  any capability or authorization check when saving its holiday schedule,
  allowing unauthenticated attackers to overwrite the dates the booking system
  treats as un…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-284
product: Rox Appointment Booking
affected:
  - rox_appointment_booking < 1.2.0
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87891'
references:
  - url: 'https://wpscan.com/vulnerability/e7f3b29e-2503-41bb-b15c-3c0ef71a3a00/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00343
epssPercentile: 0.25034
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-12T15:15:56.284102Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
