medium · CVSS v3 4.8 · EPSS 0.00132
CVE-2026-91847
The Online Scheduling and Appointment Booking System WordPress plugin before version 28.2 fails to validate conversation ownership during un
Overview
The Online Scheduling and Appointment Booking System WordPress plugin before version 28.2 fails to validate conversation ownership during unauthenticated AI booking-assistant actions. This flaw allows unauthenticated visitors to read and inject messages into other users' active conversations. It matters because it exposes private communications within the scheduling interface.
Description
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
Impact
The vulnerability primarily impacts confidentiality and integrity by exposing sensitive communication content and allowing unauthorized message injection. Unauthenticated external attackers can access active booking assistant conversations belonging to other users. No administrative privileges are required to exploit this condition, increasing the exposure window for affected deployments. The attack does not allow direct system compromise or remote code execution, but it impacts data privacy.
Remediation
Update the Online Scheduling and Appointment Booking System WordPress plugin to version 28.2 or later where conversation verification is properly enforced. Implement web application firewall (WAF) rules to monitor and block suspicious unauthenticated requests targeting AI conversation endpoints if immediate patching is not feasible. Review plugin access logs for anomalies indicating unauthorized access to conversation IDs.
Risk context
This vulnerability is rated as medium severity with a CVSS v3 score of 4.8, reflecting moderate risk due to the lack of authentication requirements for exploitation. The EPSS score of 0.00132 indicates a currently low probability of active exploitation in the wild. Remediation should be prioritized during standard maintenance cycles.
Affected products
- Online Scheduling and Appointment Booking System WordPress plugin
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.8
- CVSS v4
- —
- EPSS
- 0.00132