Sceawere
Vulnerability Detail
CVE-2026-6723UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Simply Schedule Appointments Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- croixhaug
- Product
- Simply Schedule Appointments
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-10T05:16:40.147Z",
"pubdate": "2026-10-10T05:16:40.147Z",
"executiveSummary": "The Simply Schedule Appointments Booking Plugin for WordPress contains a critical Incorrect Authorization vulnerability affecting all versions up to and including 1.6.11.11.\nThe vulnerability resides in the plugin's REST API appointment update endpoint, which fails to adequately sanitize or restrict user-supplied input.\nBy manipulating the request, an attacker can bypass authorization controls to modify appointment data that is intended to be protected or restricted to administrative oversight.\nThis flaw allows unauthorized actors to perform sensitive operations such as falsifying payment confirmations, reassigning appointment ownership, or altering core service configurations.\nThe impact is significant, potentially leading to unauthorized business logic manipulation and loss of data integrity within the booking system.\nExploitation does not require elevated administrative privileges; the vulnerability is accessible via token-authenticated requests, effectively allowing standard users or unauthorized entities to perform administrative-level modifications on appointment objects.\nOrganizations using this plugin are at risk of service disruption and financial inconsistencies due to tampered booking records.",
"technicalDetails": "The vulnerability is rooted in an improper implementation of authorization checks within the REST API endpoint responsible for processing appointment updates.\nSpecifically, the plugin's backend logic fails to implement a robust field-level whitelist for the update request parameters, allowing input passed via the REST API to overwrite sensitive internal object properties.\nThe component responsible for handling appointment modifications does not verify whether the requesting token-authenticated user possesses the necessary administrative permissions before committing changes to the database.\nThe attack flow involves an adversary capturing or crafting a valid REST API request targeting the appointment update endpoint. By injecting specific key-value pairs into the payload, the attacker can influence fields that should be reserved for administrative modification.\nFor example, an attacker can modify the 'payment_status' field to indicate a transaction has been processed even when it has not, or alter the 'user_id' associated with an appointment to hijack or reassign bookings. Furthermore, the ability to change the 'service_type' allows an attacker to manipulate the underlying booking parameters, potentially bypassing price tiers or service availability constraints.\nBecause the validation logic is missing at the architectural level of the endpoint, the application trusts the incoming request object implicitly. The vulnerability persists across all versions up to 1.6.11.11, indicating a systemic failure in the plugin's API security boundary.\nSuccessful exploitation results in full control over appointment metadata. From an attacker's perspective, this provides a mechanism to facilitate fraud or operational sabotage without needing to compromise the WordPress administrator account directly. The lack of granular control over permitted fields in the update mechanism effectively turns a standard authenticated booking update request into a privilege escalation vector for object manipulation."
}