PatchSiren

Online Scheduling and Appointment Booking System CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Online Scheduling and Appointment Booking System CVE published 2026-09-27

CVE-2026-86841

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 has a critical vulnerability. This vulnerability allows users with a custom booking-management capability to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. Defenders should assess exposure and prioritize verification of the plugin version and restriction of the custom bo [truncated]