Sceawere
Vulnerability Detail
CVE-2026-94074UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Broken Access Control Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- NSquared
- Product
- Simply Schedule Appointments
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:22.947Z",
"pubdate": "2026-09-30T13:17:22.947Z",
"executiveSummary": "The Simply Schedule Appointments plugin for WordPress, specifically versions 1.6.12.29 and earlier, is susceptible to an unauthenticated broken access control vulnerability. This flaw allows unauthorized remote attackers to bypass existing security restrictions and perform unauthorized actions within the plugin's environment without requiring valid authentication or specific user privileges.\nThe vulnerability stems from improper validation of authorization checks on sensitive administrative or data-processing endpoints. By failing to verify the session status or the capability level of the requesting entity, the plugin exposes critical functionalities to the public internet.\nThe primary risk implication is the potential for unauthorized data manipulation, configuration changes, or unauthorized access to sensitive scheduling data, which could lead to a compromise of the affected WordPress site's operational integrity. Because this vulnerability is exploitable by an unauthenticated attacker, the risk to the availability and confidentiality of the scheduling system is high. Exploitation does not require prior knowledge of a valid account, making it a significant concern for all installations within the specified version range.",
"technicalDetails": "The vulnerability resides in the way Simply Schedule Appointments handles internal requests to its REST API or AJAX-based endpoints. The root cause is the absence of adequate `current_user_can()` capability checks or nonce verification within the vulnerable functions responsible for processing administrative or privileged tasks.\nUnder normal operating conditions, these endpoints are intended to be restricted to users with administrative or specific plugin-defined capabilities. However, in versions 1.6.12.29 and earlier, the application logic fails to properly enforce these access controls during the execution of critical code paths. Consequently, an unauthenticated user can craft malicious HTTP requests—typically GET or POST requests directed at specific plugin API routes—that trigger restricted functions.\nThe attack flow proceeds as follows: 1) The attacker identifies the exposed endpoint within the plugin's codebase, often associated with administrative scheduling configurations or settings management. 2) The attacker transmits a crafted request to this endpoint. 3) The server-side logic processes the request, bypassing the security gate that should have rejected the request due to a lack of valid authentication credentials. 4) The plugin performs the requested action, such as modifying appointment settings, extracting sensitive information, or updating internal state variables.\nThe impact of this post-exploitation behavior is significant, as it grants attackers the ability to manipulate scheduling infrastructure, potentially leading to unauthorized service disruption, the exfiltration of personally identifiable information (PII) related to appointments, or the alteration of site settings. Since the vulnerability is located at the application layer, the exploitation occurs over the standard HTTP/HTTPS protocol and does not require complex or exotic injection techniques. This makes the flaw highly accessible to automated scanning tools and script-based exploitation campaigns. The lack of authentication requirements facilitates large-scale automated discovery and exploitation across the WordPress ecosystem, posing a systemic risk to sites utilizing these vulnerable versions."
}