PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86839 WordPress.org CVE debrief

CVE-2026-86839 debrief based on CVE Program and NVD records. The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. This issue affects defenders of WordPress installations with the Online Scheduling and Appointment Booking System plugin, particularly those with staff-level accounts.

Vendor
WordPress.org
Product
Online Scheduling and Appointment Booking System
CVSS
LOW 3.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-09-28
Advisory published
2026-09-27
Advisory updated
2026-09-28

Who should care

Defenders of WordPress installations with the Online Scheduling and Appointment Booking System plugin, particularly those with staff-level accounts, should be aware of this vulnerability. They should assess their exposure, verify staff role permissions, and implement necessary controls to prevent unauthorized access and modifications. Additionally, operators of affected systems, platform administrators, and security teams should prioritize verifying and -

Why it matters

CVE-2026-86839 allows authenticated attackers with staff-level accounts to view, modify, and delete other staff members' appointments and payments, including customer personal information.

  • Potential unauthorized access to sensitive customer information
  • Possible modification or deletion of appointments and payments
  • Verification of staff role permissions and access controls is necessary
  • Monitoring for unauthorized access or modifications is required

Technical summary

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. This issue arises from inadequate access control in the plugin's staff-role AJAX actions, potentially leading to unauthorized access and modification of sensitive customer information.

Defensive priority

Assess exposure and verify staff role permissions

Recommended defensive actions

  • Verify staff role permissions and access controls
  • Restrict access to appointment and payment records
  • Monitor for unauthorized access or modifications
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86839 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86839

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86839 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86839

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.