Improper Access Control in Online Scheduling and Appointment Booking System by WordPress
CVE-2026-86839
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 September 2026
Badges
What is CVE-2026-86839?
The Online Scheduling and Appointment Booking System plugin for WordPress fails to adequately verify the ownership of appointment and payment records during AJAX requests made by staff members. This flaw allows authenticated users with staff-level accounts to access, alter, and delete appointments and payments belonging to other staff members, potentially exposing sensitive customer information. Affected versions prior to 28.3 lack the necessary checks, highlighting a significant security concern for organizations relying on this plugin for appointment management.
Affected Version(s)
Online Scheduling and Appointment Booking System 0 < 28.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.