rootpwn

medium · CVSS v3 4.8 · EPSS 0.00132

CVE-2026-91847

The Online Scheduling and Appointment Booking System WordPress plugin before version 28.2 fails to validate conversation ownership during un

Overview

The Online Scheduling and Appointment Booking System WordPress plugin before version 28.2 fails to validate conversation ownership during unauthenticated AI booking-assistant actions. This flaw allows unauthenticated visitors to read and inject messages into other users' active conversations. It matters because it exposes private communications within the scheduling interface.

Description

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.

Impact

The vulnerability primarily impacts confidentiality and integrity by exposing sensitive communication content and allowing unauthorized message injection. Unauthenticated external attackers can access active booking assistant conversations belonging to other users. No administrative privileges are required to exploit this condition, increasing the exposure window for affected deployments. The attack does not allow direct system compromise or remote code execution, but it impacts data privacy.

Remediation

Update the Online Scheduling and Appointment Booking System WordPress plugin to version 28.2 or later where conversation verification is properly enforced. Implement web application firewall (WAF) rules to monitor and block suspicious unauthenticated requests targeting AI conversation endpoints if immediate patching is not feasible. Review plugin access logs for anomalies indicating unauthorized access to conversation IDs.

Risk context

This vulnerability is rated as medium severity with a CVSS v3 score of 4.8, reflecting moderate risk due to the lack of authentication requirements for exploitation. The EPSS score of 0.00132 indicates a currently low probability of active exploitation in the wild. Remediation should be prioritized during standard maintenance cycles.

Affected products

  • Online Scheduling and Appointment Booking System WordPress plugin

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.8
CVSS v4
EPSS
0.00132

wordpress plugin unauthenticated information-disclosure ai-assistant medium-severity cve

← All CVEs