Croixhaug · The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin · CVE-2026-6937
**Name of the Vulnerable Software and Affected Versions**
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin versions prior to 1.6.11.9
**Description**
Missing authorization in the bulk appointments REST API endpoint allows unauthenticated attackers to modify arbitrary appointment records. This includes the ability to change customer PII (Personally Identifiable Information), payment status, and meeting URL fields. Additionally, full customer PII can be exposed through the bulk endpoint response. The issue stems from the use of a public nonce—a static, user-independent security token—found in the HTML source of pages using the `[ssa booking]` shortcode, which allows any visitor to bypass authentication.
**Recommendations**
Update the plugin to a version newer than 1.6.11.8.