Sceawere

Vulnerability Detail

CVE-2026-39756UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Wappointment Unauthenticated IDOR Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
16h ago
Vendor
Wappointment team
Product
Wappointment
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-06T09:17:47.387Z",
  "pubdate": "2026-10-06T09:17:47.387Z",
  "executiveSummary": "The Wappointment plugin for WordPress is susceptible to an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability affecting versions 2.7.7 and earlier.\nThis vulnerability stems from a failure to implement proper authorization checks on critical data retrieval endpoints.\nUnauthenticated remote attackers can exploit this flaw to bypass access controls and gain unauthorized access to sensitive application data or internal objects that should be restricted to administrative or authorized users.\nThe risk is categorized as critical because it allows for the exfiltration of information without requiring valid credentials or active session tokens.\nThe attack vector is network-based, utilizing simple HTTP requests to manipulate object identifiers. Impact includes unauthorized information disclosure and potential reconnaissance for further exploitation.",
  "technicalDetails": "The vulnerability resides in the core architecture of Wappointment version 2.7.7 and earlier, specifically within the plugin's data handling logic for object-based requests.\nRoot cause analysis indicates that the plugin lacks server-side authorization validation when processing requests directed at specific object references. While the system expects a user to be authenticated or possess specific capabilities, the code fails to verify the requester's session or permissions before processing the requested object identifier.\nExploitation is achieved through IDOR (Insecure Direct Object Reference) patterns, where an attacker modifies input parameters such as numeric IDs or slug identifiers within a URL or a POST/GET parameter. By incrementing or substituting these values in the request, the attacker directs the application to return data objects—such as appointment details, user configurations, or sensitive backend records—that belong to other users or administrators.\nThe attack flow follows a predictable sequence: First, the attacker identifies the vulnerable endpoint exposed by the plugin. Second, the attacker interacts with the endpoint, often by substituting a known or guessed ID into the request payload. Third, because the application does not perform a permission check against the current security context, the server retrieves the record from the database and returns it in the HTTP response body.\nThis vulnerability is particularly severe because it is entirely unauthenticated. It does not require knowledge of internal WordPress nonces, valid cookies, or administrative privileges to successfully execute the retrieval of restricted data. Because the system relies on the assumption that only legitimate users will reach these endpoints, it fails to enforce 'Zero Trust' principles at the individual resource access level.\nThe post-exploitation impact typically involves unauthorized disclosure of sensitive data, such as appointment logs, client personal identifiable information (PII), or system settings. Furthermore, this type of vulnerability can serve as a primary step in a multi-stage attack chain, providing attackers with the necessary internal object identifiers required to perform more destructive operations elsewhere in the plugin's functionality."
}
CVE-2026-39756: Wappointment Unauthenticated IDOR Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere