PT-2026-90587 · Undefined · Undefined
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rox Appointment Booking versions prior to 1.2.0
Description
The plugin fails to verify the order total or the selected payment method against server-side pricing during the booking creation process. This allows unauthenticated attackers to create confirmed bookings at an arbitrary price and bypass configured payment-method restrictions.
Recommendations
Update Rox Appointment Booking to version 1.2.0 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined