MEDIUM
Online Scheduling and Appointment Booking System
CVE published 2026-09-27
CVE-2026-86841
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 has a critical vulnerability. This vulnerability allows users with a custom booking-management capability to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. Defenders should assess exposure and prioritize verification of the plugin version and restriction of the custom bo [truncated]