Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9188— Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter

CVSS 5.3 · Medium EPSS 0.30% · P22

Affected Version Matrix 1

Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9188

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointment `edit_key` — the sole authorization token consumed by `tryCancel()` — being generated as a predictable, unsalted MD5 hash of only `client_id` (a sequential integer), `start_at` (a publicly observable appointment timestamp), and `staff_id` (a small enumerable integer), with no secret salt or random component, and the unauthenticated cancellation and rescheduling REST endpoints performing no ownership or identity verification beyond matching this reconstructible key. This makes it possible for unauthenticated attackers to compute valid `edit_key` values for appointments belonging to other users and cancel or reschedule those appointments arbitrarily. Exploitation requires the `allow_cancellation` or `allow_rescheduling` setting to be enabled on the site, both of which are common configurations for active booking deployments; an attacker can obtain the inputs needed to reconstruct a victim's key by booking their own appointment to observe their sequential `client_id` and correlating publicly visible appointment times and enumerable staff identifiers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Appointment Bookings for Zoom GoogleMeet and more – Wappointment 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress Appointment Bookings for Zoom GoogleMeet and more – Wappointment是WordPress基金会的一款免费的 WordPress 预约插件,能让客户通过一个直观的表格,轻松预约 Zoom、Google Meet 等线上会议、电话或线下会面。 WordPress Appointment Bookings for Zoom GoogleMeet and more – Wappointment 2.7.6及之前版本存在授权问题漏洞,该
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
wappointmentAppointment Bookings for Zoom GoogleMeet and more – Wappointment 0 ~ 2.7.6 -

II. Public POCs for CVE-2026-9188

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9188

登录查看更多情报信息。

Patches & Fixes for CVE-2026-9188 (8)

Vendor Advisories for CVE-2026-9188 (1)

Other References for CVE-2026-9188 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9188

No comments yet


Leave a comment