CVE-2026-91847: CWE-639 Authorization Bypass Through User-Controlled Key in Online Scheduling and Appointment Booking System
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
AI Analysis
Technical Summary
CVE-2026-91847 is an authorization bypass vulnerability (CWE-639) in the Online Scheduling and Appointment Booking System WordPress plugin versions 28.1 up to but not including 28.2. The vulnerability arises because the plugin fails to verify that the requester owns the AI booking-assistant conversation referenced in unauthenticated conversation actions. This allows any unauthenticated visitor to read messages from another visitor's assistant conversation and inject messages into that conversation.
Potential Impact
An attacker can access sensitive conversation data of other users without authentication and manipulate ongoing conversations by injecting messages. This compromises the confidentiality and integrity of user interactions with the AI booking assistant, potentially leading to misinformation or unauthorized actions within the scheduling system.
Mitigation Recommendations
Upgrade the Online Scheduling and Appointment Booking System WordPress plugin to version 28.2 or later, where this authorization bypass vulnerability is fixed. No other mitigation steps are indicated.
CVE-2026-91847: CWE-639 Authorization Bypass Through User-Controlled Key in Online Scheduling and Appointment Booking System
Description
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
CVSS v3.1
Score 4.8medium
Affected software
Online Scheduling and Appointment Booking System
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91847 is an authorization bypass vulnerability (CWE-639) in the Online Scheduling and Appointment Booking System WordPress plugin versions 28.1 up to but not including 28.2. The vulnerability arises because the plugin fails to verify that the requester owns the AI booking-assistant conversation referenced in unauthenticated conversation actions. This allows any unauthenticated visitor to read messages from another visitor's assistant conversation and inject messages into that conversation.
Potential Impact
An attacker can access sensitive conversation data of other users without authentication and manipulate ongoing conversations by injecting messages. This compromises the confidentiality and integrity of user interactions with the AI booking assistant, potentially leading to misinformation or unauthorized actions within the scheduling system.
Mitigation Recommendations
Upgrade the Online Scheduling and Appointment Booking System WordPress plugin to version 28.2 or later, where this authorization bypass vulnerability is fixed. No other mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-15T08:36:37.677Z
- State
- PUBLISHED
Threat ID: 6aae2c6955bf5e2cf5363adc
Added to database: 09/19/2026, 06:32:09 UTC
Last enriched: 09/19/2026, 06:46:54 UTC
Last updated: 09/20/2026, 01:51:57 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.