Description
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in NSquared’s Simply Schedule Appointments plugin. It allows an attacker who can send a request to the plugin to bypass configured access controls and access or modify appointment data. The flaw is classified as CWE‑862, meaning it can lead to unauthorized information disclosure or alteration within the application, potentially enabling privilege escalation if the attacker can target privileged appointments or booking functions.

Affected Systems

Affected product: NSquared’s Simply Schedule Appointments plugin for WordPress. Versions from the earliest release through and including 1.6.12.4 are impacted. Any WordPress site that has this plugin installed and has not applied a newer version beyond 1.6.12.4 is vulnerable.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate threat. The EPSS score of less than 1% indicates a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need to reach the plugin over the web; based on the nature of the vulnerability, it is inferred that HTTP requests or crafted URLs could be used to exploit the bypass. No special prerequisites beyond the plugin being exposed and the target site being accessible are required, making exploitation technically straightforward for a determined attacker.

Generated by OpenCVE AI on August 1, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Simply Schedule Appointments to a newer version that addresses the access control issue.
  • If upgrade is not feasible, disable or remove the plugin from the WordPress installation to prevent exposure.
  • Verify that user roles and capabilities in WordPress are properly configured so that only administrators can access appointment management features; adjust any custom role mappings.
  • Monitor web logs for suspicious activity targeting appointment management URLs.

Generated by OpenCVE AI on August 1, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress
Vendors & Products Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.
Title WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Nsquared Simply Schedule Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:58:26.493Z

Reserved: 2026-06-25T08:05:16.223Z

Link: CVE-2026-57812

cve-icon Vulnrichment

Updated: 2026-07-13T13:58:21.808Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses