Impact
The vulnerability is a missing authorization flaw (CWE‑862) that allows unauthenticated or improperly authenticated users to perform privileged actions within the Simply Schedule Appointments plugin. This defect exposes appointment data and functions that should be restricted, enabling attackers to schedule, modify, or view appointments without proper rights, leading to privacy breaches or service disruption.
Affected Systems
The plugin is distributed by NSquared under the name Simply Schedule Appointments. Versions up to and including 1.6.11.11 are affected. Any WordPress site using an affected version of the plugin may be exploited if the missing authorization is present.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the very low EPSS of less than 1% suggests a small current exploit probability and it is not listed in CISA’s KEV catalog. Attackers can leverage the vulnerability by sending crafted requests from a WordPress site that hosts the affected plugin; although the description does not explicitly state whether authentication is required, the nature of a broken access control flaw makes it reasonable to infer that the attack may succeed with a low‑privilege WordPress user or even anonymously if the plugin exposes endpoints without authentication checks. The potential impact includes unauthorized access to appointment data and manipulation of scheduling functions.
OpenCVE Enrichment