Executive brief
Simply Schedule Appointments is a WordPress plugin used by businesses to manage online bookings and appointments. A security flaw in the plugin allows unauthorized individuals to bypass intended access controls due to missing authorization checks. This could allow an attacker to perform actions or access information that should be restricted to administrators, potentially disrupting scheduling operations or exposing appointment data.
Technical details
The vulnerability is classified as Missing Authorization (CWE-862) within the Simply Schedule Appointments plugin. It stems from a failure to properly validate user permissions or security levels before executing certain functions, leading to broken access control. An unauthenticated remote attacker can exploit this flaw to perform actions that should require higher privileges. The issue affects all versions up to and including 1.6.11.11 and is resolved in version 1.6.12.0.
Affected products
- NSquared Simply Schedule Appointments <= 1.6.11.11
Timeline
- 2026-05-07: disclosed: Reported by anhcd05 to Patchstack
- 2026-07-09: advisory: Patchstack published the vulnerability details
- 2026-07-13: advisory: CVE published in the NVD dataset