Executive brief
Simply Schedule Appointments is a popular WordPress plugin used by businesses to manage customer bookings and scheduling. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to administrators or specific staff members. This could lead to unauthorized changes to appointment settings or disruption of the scheduling service, potentially impacting business operations and customer trust.
Technical details
The vulnerability is classified as Missing Authorization (CWE-862) within the Simply Schedule Appointments plugin. It stems from a failure to properly validate user permissions or security tokens (nonces) when processing certain requests, allowing an unauthenticated attacker to execute actions intended for higher-privileged users. The flaw specifically impacts versions up to and including 1.6.12.4. An attacker can leverage this to modify plugin configurations or disrupt service availability. The issue is resolved in version 1.6.12.6.
Affected products
- NSquared Simply Schedule Appointments <= 1.6.12.4
Timeline
- 2026-06-11: disclosed: Reported by researcher hio to Patchstack
- 2026-07-09: advisory: Patchstack published advisory details
- 2026-07-13: advisory: CVE published to NVD dataset
- 2026-07-13: patched: Version 1.6.12.6 confirmed as patched version