Sceawere

Vulnerability Detail

CVE-2026-94673UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated IDOR in Simply Schedule Appointments

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
NSquared
Product
Simply Schedule Appointments
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-30T13:17:27.267Z",
  "pubdate": "2026-09-30T13:17:27.267Z",
  "executiveSummary": "The Simply Schedule Appointments plugin, specifically versions 1.6.12.31 and below, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows unauthenticated attackers to access, view, or manipulate sensitive appointment data or plugin-related objects by manipulating object identifiers in requests.\nThe flaw stems from a failure to implement adequate access control checks on server-side request processing for specific endpoints.\nBecause the vulnerability is exploitable by unauthenticated remote actors, it poses a significant risk to data confidentiality and integrity within the WordPress environment.\nSuccessful exploitation requires no prior authentication, enabling an attacker to potentially exfiltrate personal information, modify scheduling configurations, or gain unauthorized visibility into appointment logistics without interaction from a system administrator.",
  "technicalDetails": "The vulnerability is an Insecure Direct Object Reference (IDOR) located within the plugin's request handling logic. An IDOR occurs when an application exposes a reference to an internal implementation object, such as a database key or a file path, without performing adequate authorization checks to ensure the requesting user is permitted to access that object.\nIn the context of Simply Schedule Appointments <= 1.6.12.31, the plugin fails to validate whether the unauthenticated user initiating the request possesses the necessary permissions to retrieve or modify the targeted appointment resource.\nThe attack flow involves an attacker identifying a predictable or discoverable object ID (e.g., an appointment ID) through parameter enumeration or information leakage. The attacker then crafts a malicious request targeting the vulnerable plugin endpoint, substituting the legitimate ID with the targeted resource ID.\nBecause the backend function responsible for processing these requests lacks an authorization layer—such as a nonces verification or a capability check (e.g., current_user_can())—the server proceeds to execute the requested action against the specified object, returning the requested data or performing the modification on behalf of the unauthenticated attacker.\nThis vulnerability is particularly critical due to its unauthenticated nature and the potential for large-scale data harvesting. An attacker could iterate through sequential or predictable ID ranges to scrape the entire appointment database, leading to mass exposure of customer or administrator data. Furthermore, if the affected endpoint supports write operations, the attacker might be able to cancel, reschedule, or modify appointment data, leading to a significant disruption of business operations and a loss of system integrity.\nThe root cause is a deficiency in the design of the plugin's API endpoints, which rely on client-provided input for resource identification without enforcing a secondary authorization gate. This bypasses the standard WordPress security model where such requests would typically be intercepted and validated for user roles and privileges prior to object instantiation or retrieval.\nThe exposure is network-wide, provided the target site is reachable, and requires no specific privilege levels, making it highly attractive for automated exploitation scripts."
}
CVE-2026-94673: Unauthenticated IDOR in Simply Schedule Appointments (MEDIUM Severity, CVSS: 5.3) | Sceawere