CVE-2026-6723
Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.
| CWE | CWE-863 |
| Vendor | croixhaug |
| Product | simply schedule appointments |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for croixhaug simply schedule appointments
Be the first to know when new medium vulnerabilities affecting croixhaug simply schedule appointments are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
croixhaug / Simply Schedule Appointments
0 ≤ 1.6.11.11
References
Credits
awhacken