Description
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: unauthenticated modification of sensitive appointment data
Action: Immediate Patch
AI Analysis

Impact

The Simply Schedule Appointments plugin for WordPress is vulnerable to an incorrect authorization flaw in its appointment update REST API endpoint. The endpoint does not restrict which fields a token‑authenticated customer can modify, allowing an unauthenticated attacker to alter admin‑controlled appointment fields. This can be used to falsify payment confirmation, reassign the appointment to a different user, and change the service type.

Affected Systems

All installations of the Simply Schedule Appointments WordPress plugin with versions up to and including 1.6.11.11 are affected. The vendor is croixhaug and any WordPress site that deploys this plugin at those versions is potentially impacted.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability has moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires sending a crafted request to the appointment update API; because the API accepts public tokens and does not enforce proper authorization checks, an attacker can change sensitive appointment data without authentication. The ability to alter payment status, reassign appointments, and modify service types represents a significant risk to the integrity and trustworthiness of the scheduling system.

Generated by OpenCVE AI on October 10, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the newest version of the Simply Schedule Appointments plugin, 1.6.11.12 or later.
  • If an upgrade is not immediately possible, restrict write access on the appointment update API to authenticated administrative roles or block the endpoint entirely.
  • Ensure that appointment public tokens are kept confidential and considered for renewal or restriction to reduce the window of opportunity for abuse.

Generated by OpenCVE AI on October 10, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.
Title Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:46.386Z

Reserved: 2026-04-20T19:51:21.160Z

Link: CVE-2026-6723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:40.147

Modified: 2026-10-10T05:16:40.147

Link: CVE-2026-6723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses