CVE-2026-91847
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
- Published Sep 19, 2026
- CVSS 4.8 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available