{"id":"CVE-2026-91847","published":"2026-09-19T07:16:33.480","lastModified":"2026-09-21T13:34:57.127","description":"The Online Scheduling and Appointment Booking System  WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.","cvssScore":4.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/9eef3086-3a67-4ee2-bd78-e346e7b05d62/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}