PT-2026-44216 · Croixhaug+1 · The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin versions prior to 1.6.11.9
Description
Missing authorization in the bulk appointments REST API endpoint allows unauthenticated attackers to modify arbitrary appointment records. This includes the ability to change customer PII (Personally Identifiable Information), payment status, and meeting URL fields. Additionally, full customer PII can be exposed through the bulk endpoint response. The issue stems from the use of a public nonce—a static, user-independent security token—found in the HTML source of pages using the
[ssa booking] shortcode, which allows any visitor to bypass authentication.Recommendations
Update the plugin to a version newer than 1.6.11.8.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
Simply Schedule Appointments