---
id: CVE-2026-87907
title: >-
  The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform
  any authorization check on the endpoints that return booking service and
  category records, allowing unauthenticated attackers to read the private
  internal notes …
summary: >-
  The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform
  any authorization check on the endpoints that return booking service and
  category records, allowing unauthenticated attackers to read the private
  internal notes …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Rox Appointment Booking
affected:
  - rox_appointment_booking < 1.2.8
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:57.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87907'
references:
  - url: 'https://wpscan.com/vulnerability/60f70070-f785-43a2-be51-c01e64fb1821/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:15:14.413657Z'
epss: 0.00345
epssPercentile: 0.25183
ingestedAt: '2026-09-16T06:51:06.256Z'
---

## Overview

The Rox Appointment Booking  WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
