Executive brief
The Smart Appointment & Booking plugin for WordPress, used to manage customer schedules, contains a security flaw that allows unauthorized individuals to cancel appointments. By exploiting a logic error in how the plugin verifies requests, an attacker can delete any booking without needing to log in. This could lead to significant operational disruption and loss of customer trust for businesses relying on the plugin for their scheduling.
Technical details
The vulnerability exists in the saab_cancel_booking() function within the Smart Appointment & Booking plugin for WordPress (versions up to 1.0.8). The root cause is a combination of missing capability checks and a logic error in nonce validation where the code uses an 'AND' (&&) operator instead of an 'OR' (||) operator. This flaw allows the security check to be bypassed if any value is provided for the security parameter. An unauthenticated remote attacker can exploit this by sending a request with a predictable booking ID to cancel arbitrary appointments. The plugin has been temporarily closed on the WordPress repository pending review.
Affected products
- ZealousWeb Smart Appointment & Booking Up to, and including, 1.0.8
Timeline
- 2026-05-06: other: Plugin temporarily closed on WordPress.org repository
- 2026-05-12: disclosed: Vulnerability published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/smart-appointment-booking/tags/1.0.8/inc/front/class.saab.front.action.php
- https://plugins.trac.wordpress.org/browser/smart-appointment-booking/trunk/inc/front/class.saab.front.action.php
- https://wordpress.org/plugins/smart-appointment-booking/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/afc3531d-6134-4b45-b532-37430d96a8fb?source=cve