Junglewise Threat Intelligence

CVE-2026-16540: Simply Schedule Appointments authorization bypass in appointment purge

CVE-2026-16540 · Severity: high · CVSS 7.5 · Published 2026-08-02

Technologies: Simply Schedule Appointments. Vendors: Simply Schedule Appointments.

Executive brief

Simply Schedule Appointments is a WordPress plugin that manages appointment bookings for businesses. The plugin fails to properly validate user permissions on bulk appointment operations, allowing unauthenticated attackers to download a CSV backup containing all customer personal data (names, emails, phone numbers, payment info) from the site. On premium editions with staff features enabled, attackers can also permanently delete all past, abandoned, and canceled appointments across the entire site.

Technical details

This is a broken access control vulnerability (CWE-863) in the `/wp-json/ssa/v1/appointments/purge` REST endpoint. The plugin uses per-appointment tokens to restrict operations, but fails to validate that the authenticated token can only perform actions on that specific appointment. An attacker who makes a legitimate free appointment booking obtains their own appointment ID and public token; they can then reuse this token with different query parameters (purge_past_appointments, purge_abandoned_appointments, purge_all_canceled_appointments) to trigger site-wide deletion of all matching appointments. The backup CSV is written before deletion is processed, allowing data exfiltration even on free editions where deletion rolls back. The attack is entirely unauthenticated after the initial booking, requires no admin privileges, and is network-accessible via the REST API. Fixed in version 1.6.12.6.

Affected products

  • Simply Schedule Appointments Simply Schedule Appointments before 1.6.12.6

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: patched: Fixed in version 1.6.12.6

References

Related threats