Improper Access Control in Online Scheduling and Appointment Booking System by WordPress
CVE-2026-86839

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-86839?

The Online Scheduling and Appointment Booking System plugin for WordPress fails to adequately verify the ownership of appointment and payment records during AJAX requests made by staff members. This flaw allows authenticated users with staff-level accounts to access, alter, and delete appointments and payments belonging to other staff members, potentially exposing sensitive customer information. Affected versions prior to 28.3 lack the necessary checks, highlighting a significant security concern for organizations relying on this plugin for appointment management.

Affected Version(s)

Online Scheduling and Appointment Booking System 0 < 28.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vũ Quang Huy
WPScan
.