CVE-2026-87891 | Rox Appointment Booking Plugin up to 1.1.x on WordPress Holiday Schedule access control
A vulnerability marked as critical has been reported in Rox Appointment Booking Plugin up to 1.1.x on WordPress. The affected element is an unknown function of the component Holiday Schedule. This manipulation causes improper access controls.
This vulnerability is tracked as CVE-2026-87891. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More