CVE-2026-86841
4.7 MEDIUMPublished 2026-09-27 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-502
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-59953PoC
- CRITICALCVE-2025-66455PoC
- HIGHCVE-2026-100308PoC
- HIGHCVE-2026-100841PoC
- HIGHCVE-2026-100843PoC
- HIGHCVE-2026-100845PoC
- HIGHCVE-2026-100846PoC
- UNSCOREDCVE-2026-101169
Related by shared AI tags and CWE weakness class. Browse the full archive.