Junglewise Threat Intelligence

CVE-2026-39694: NSquared Simply Schedule Appointments missing authorization

CVE-2026-39694 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: NSquared Simply Schedule Appointments.

Executive brief

Simply Schedule Appointments is a WordPress plugin used by businesses to manage online bookings and scheduling. A security flaw in the plugin's access control settings allows unauthorized individuals to bypass intended security levels. This could potentially allow an attacker to modify scheduling configurations or perform actions that should be restricted to administrators, impacting the integrity of the booking system.

Technical details

A missing authorization (CWE-862) vulnerability exists in the NSquared Simply Schedule Appointments plugin for WordPress. The flaw stems from a failure to properly validate user permissions or security levels within the plugin's access control logic. An unauthenticated remote attacker can exploit this to perform actions or access functionality that should be restricted to higher-privileged users. The vulnerability is present in versions up to and including 1.6.10.2 (with some reports indicating up to 1.6.11.0). Users are advised to update to version 1.6.11.1 or later to remediate the issue.

Affected products

  • NSquared Simply Schedule Appointments <= 1.6.10.2 (and up to 1.6.11.0 per some sources)

Timeline

  • 2026-01-27: other: Reported by researcher hhhai
  • 2026-02-26: disclosed: Initial disclosure by Patchstack
  • 2026-02-26: patched: Patch released in version 1.6.11.1
  • 2026-04-08: advisory: CVE published

References