Impact
The Simply Schedule Appointments plugin for WordPress is vulnerable to an incorrect authorization flaw in its appointment update REST API endpoint. The endpoint does not restrict which fields a token‑authenticated customer can modify, allowing an unauthenticated attacker to alter admin‑controlled appointment fields. This can be used to falsify payment confirmation, reassign the appointment to a different user, and change the service type.
Affected Systems
All installations of the Simply Schedule Appointments WordPress plugin with versions up to and including 1.6.11.11 are affected. The vendor is croixhaug and any WordPress site that deploys this plugin at those versions is potentially impacted.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability has moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires sending a crafted request to the appointment update API; because the API accepts public tokens and does not enforce proper authorization checks, an attacker can change sensitive appointment data without authentication. The ability to alter payment status, reassign appointments, and modify service types represents a significant risk to the integrity and trustworthiness of the scheduling system.
OpenCVE Enrichment