Sceawere

Vulnerability Detail

CVE-2026-89294UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Simply Schedule Appointments LFI Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
croixhaug
Product
Simply Schedule Appointments
Attack Type
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T07:16:30.947Z",
  "pubdate": "2026-09-30T07:16:30.947Z",
  "executiveSummary": "The Simply Schedule Appointments plugin for WordPress, in versions up to and including 1.6.12.27, contains a critical Local File Inclusion (LFI) vulnerability.\nThe flaw stems from improper input validation within the 'ssa_locale' parameter, which is processed during the 'plugins_loaded' hook.\nThis vulnerability allows an attacker to include and execute arbitrary .php files residing on the server, potentially leading to full Remote Code Execution (RCE) and complete system compromise.\nAlthough initially identified as requiring subscriber-level authentication, the filter is registered unconditionally and lacks necessary nonce or capability checks, rendering it exploitable by unauthenticated remote attackers.\nThe exposure facilitates unauthorized access to sensitive configuration data, database credentials, and enables an attacker to execute arbitrary server-side code, effectively bypassing standard WordPress access control mechanisms.\nGiven the severity and the ease of exploitation, this vulnerability poses a significant risk to the integrity, availability, and confidentiality of the affected WordPress environment.",
  "technicalDetails": "The vulnerability originates from the improper handling of the 'ssa_locale' parameter within the Simply Schedule Appointments plugin. The plugin registers a filter callback during the 'plugins_loaded' hook that retrieves the value directly from the global $_GET array without any sanitization or validation.\nBecause the 'plugins_loaded' action occurs early in the WordPress initialization process, the callback is executed on every request made to the server, regardless of the current user's authentication status or authorization level.\nThe root cause is the failure to implement strict allow-listing or path validation on the 'ssa_locale' parameter before it is passed to file inclusion functions. An attacker can supply a path to an existing local file containing PHP code, which the application then interprets and executes within the context of the web server process.\nThe exploitation flow is straightforward: an attacker sends a crafted HTTP request to the WordPress instance, appending the 'ssa_locale' parameter to the URL with a path pointing to a malicious or existing file on the filesystem (e.g., '/etc/passwd' or an uploaded image containing a PHP payload). The plugin's logic includes this file, triggering the execution of the injected code.\nDespite the initial assessment suggesting subscriber-level requirements, the lack of nonce verification or 'current_user_can()' capability checks means that the vulnerability is accessible to unauthenticated remote attackers. This allows for full compromise of the underlying server infrastructure if the attacker can place a file on the server, such as through an avatar upload, a separate plugin vulnerability, or by utilizing existing log files containing PHP code.\nThe impact is severe; successful exploitation results in Arbitrary Code Execution (ACE) with the privileges of the web server user. An attacker can pivot from this point to gain full administrative access to the WordPress database, exfiltrate sensitive files, or install persistent backdoors for long-term access. Furthermore, this LFI can be leveraged to read system configuration files, such as 'wp-config.php', exposing database credentials and salts, thereby compromising the security of the entire application architecture."
}
CVE-2026-89294: Simply Schedule Appointments LFI Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere