PT-2026-44216 · Croixhaug+1 · The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin+1

·

CVE-2026-6937

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin versions prior to 1.6.11.9
Description Missing authorization in the bulk appointments REST API endpoint allows unauthenticated attackers to modify arbitrary appointment records. This includes the ability to change customer PII (Personally Identifiable Information), payment status, and meeting URL fields. Additionally, full customer PII can be exposed through the bulk endpoint response. The issue stems from the use of a public nonce—a static, user-independent security token—found in the HTML source of pages using the [ssa booking] shortcode, which allows any visitor to bypass authentication.
Recommendations Update the plugin to a version newer than 1.6.11.8.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6937

Affected Products

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
Simply Schedule Appointments