Impact
The vulnerability is a Local File Inclusion flaw that allows the plugin to include and execute arbitrary PHP files via the 'ssa_locale' GET parameter. This results in the ability to run attacker supplied code, bypass authorization controls, and access sensitive data. The flaw is classified as CWE-98, reflecting improper handling of user-controlled file paths.
Affected Systems
All versions of the Simply Schedule Appointments WordPress plugin up to and including 1.6.12.27, developed by croixhaug. Users of older or unpatched installations are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the flaw can be exploited remotely via crafted URL requests and does not require authenticated access despite the original description stating subscriber-level capability is needed. Once an attacker gains ability to trigger the inclusion, they can execute arbitrary PHP code on the web server.
OpenCVE Enrichment