WordPress Plugin Vulnerabilities

Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass

Description

The plugin does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Morato Antoine
Submitter
Morato Antoine
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 2 days ago)
Added
2026-09-10 (about 1 day ago)
Last Updated
2026-09-10 (about 1 day ago)

Other