PatchSiren cyber security CVE debrief
CVE-2026-86839 WordPress.org CVE debrief
CVE-2026-86839 debrief based on CVE Program and NVD records. The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. This issue affects defenders of WordPress installations with the Online Scheduling and Appointment Booking System plugin, particularly those with staff-level accounts.
- Vendor
- WordPress.org
- Product
- Online Scheduling and Appointment Booking System
- CVSS
- LOW 3.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-28
Who should care
Defenders of WordPress installations with the Online Scheduling and Appointment Booking System plugin, particularly those with staff-level accounts, should be aware of this vulnerability. They should assess their exposure, verify staff role permissions, and implement necessary controls to prevent unauthorized access and modifications. Additionally, operators of affected systems, platform administrators, and security teams should prioritize verifying and -
Why it matters
CVE-2026-86839 allows authenticated attackers with staff-level accounts to view, modify, and delete other staff members' appointments and payments, including customer personal information.
- Potential unauthorized access to sensitive customer information
- Possible modification or deletion of appointments and payments
- Verification of staff role permissions and access controls is necessary
- Monitoring for unauthorized access or modifications is required
Technical summary
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. This issue arises from inadequate access control in the plugin's staff-role AJAX actions, potentially leading to unauthorized access and modification of sensitive customer information.
Defensive priority
Assess exposure and verify staff role permissions
Recommended defensive actions
- Verify staff role permissions and access controls
- Restrict access to appointment and payment records
- Monitor for unauthorized access or modifications
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86839 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86839
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86839 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86839
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/3ab8b879-3ef7-4aa4-8620-1bde99697dcb/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.