Impact
The vulnerability is a missing authorization flaw in NSquared’s Simply Schedule Appointments plugin. It allows an attacker who can send a request to the plugin to bypass configured access controls and access or modify appointment data. The flaw is classified as CWE‑862, meaning it can lead to unauthorized information disclosure or alteration within the application, potentially enabling privilege escalation if the attacker can target privileged appointments or booking functions.
Affected Systems
Affected product: NSquared’s Simply Schedule Appointments plugin for WordPress. Versions from the earliest release through and including 1.6.12.4 are impacted. Any WordPress site that has this plugin installed and has not applied a newer version beyond 1.6.12.4 is vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate threat. The EPSS score of less than 1% indicates a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need to reach the plugin over the web; based on the nature of the vulnerability, it is inferred that HTTP requests or crafted URLs could be used to exploit the bypass. No special prerequisites beyond the plugin being exposed and the target site being accessible are required, making exploitation technically straightforward for a determined attacker.
OpenCVE Enrichment