🔐 CVE Alert

CVE-2026-6723

MEDIUM 5.3

Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.

CWE CWE-863
Vendor croixhaug
Product simply schedule appointments
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for croixhaug simply schedule appointments

Be the first to know when new medium vulnerabilities affecting croixhaug simply schedule appointments are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

croixhaug / Simply Schedule Appointments
0 ≤ 1.6.11.11

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b6f16178-1aa3-4af2-a125-74467bc57e70?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3562241/simply-schedule-appointments

Credits

awhacken