Description
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw (CWE‑862) that allows unauthenticated or improperly authenticated users to perform privileged actions within the Simply Schedule Appointments plugin. This defect exposes appointment data and functions that should be restricted, enabling attackers to schedule, modify, or view appointments without proper rights, leading to privacy breaches or service disruption.

Affected Systems

The plugin is distributed by NSquared under the name Simply Schedule Appointments. Versions up to and including 1.6.11.11 are affected. Any WordPress site using an affected version of the plugin may be exploited if the missing authorization is present.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the very low EPSS of less than 1% suggests a small current exploit probability and it is not listed in CISA’s KEV catalog. Attackers can leverage the vulnerability by sending crafted requests from a WordPress site that hosts the affected plugin; although the description does not explicitly state whether authentication is required, the nature of a broken access control flaw makes it reasonable to infer that the attack may succeed with a low‑privilege WordPress user or even anonymously if the plugin exposes endpoints without authentication checks. The potential impact includes unauthorized access to appointment data and manipulation of scheduling functions.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Simply Schedule Appointments from any version ≤1.6.11.11 to the latest release to receive the vendor fix.
  • If an immediate upgrade is not possible, restrict the plugin’s administrative pages by configuring the WordPress capability to “manage_options” or removing the plugin’s endpoints from public access.
  • Review and tighten WordPress role permissions, ensuring that no custom or default roles grant unnecessary access to appointment‑management capabilities.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress
Vendors & Products Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
Title WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Nsquared Simply Schedule Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T10:09:02.786Z

Reserved: 2026-07-05T21:27:42.076Z

Link: CVE-2026-59523

cve-icon Vulnrichment

Updated: 2026-07-13T10:08:56.342Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses