Sceawere
Vulnerability Detail
CVE-2026-94673UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated IDOR in Simply Schedule Appointments
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- NSquared
- Product
- Simply Schedule Appointments
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-30T13:17:27.267Z",
"pubdate": "2026-09-30T13:17:27.267Z",
"executiveSummary": "The Simply Schedule Appointments plugin, specifically versions 1.6.12.31 and below, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows unauthenticated attackers to access, view, or manipulate sensitive appointment data or plugin-related objects by manipulating object identifiers in requests.\nThe flaw stems from a failure to implement adequate access control checks on server-side request processing for specific endpoints.\nBecause the vulnerability is exploitable by unauthenticated remote actors, it poses a significant risk to data confidentiality and integrity within the WordPress environment.\nSuccessful exploitation requires no prior authentication, enabling an attacker to potentially exfiltrate personal information, modify scheduling configurations, or gain unauthorized visibility into appointment logistics without interaction from a system administrator.",
"technicalDetails": "The vulnerability is an Insecure Direct Object Reference (IDOR) located within the plugin's request handling logic. An IDOR occurs when an application exposes a reference to an internal implementation object, such as a database key or a file path, without performing adequate authorization checks to ensure the requesting user is permitted to access that object.\nIn the context of Simply Schedule Appointments <= 1.6.12.31, the plugin fails to validate whether the unauthenticated user initiating the request possesses the necessary permissions to retrieve or modify the targeted appointment resource.\nThe attack flow involves an attacker identifying a predictable or discoverable object ID (e.g., an appointment ID) through parameter enumeration or information leakage. The attacker then crafts a malicious request targeting the vulnerable plugin endpoint, substituting the legitimate ID with the targeted resource ID.\nBecause the backend function responsible for processing these requests lacks an authorization layer—such as a nonces verification or a capability check (e.g., current_user_can())—the server proceeds to execute the requested action against the specified object, returning the requested data or performing the modification on behalf of the unauthenticated attacker.\nThis vulnerability is particularly critical due to its unauthenticated nature and the potential for large-scale data harvesting. An attacker could iterate through sequential or predictable ID ranges to scrape the entire appointment database, leading to mass exposure of customer or administrator data. Furthermore, if the affected endpoint supports write operations, the attacker might be able to cancel, reschedule, or modify appointment data, leading to a significant disruption of business operations and a loss of system integrity.\nThe root cause is a deficiency in the design of the plugin's API endpoints, which rely on client-provided input for resource identification without enforcing a secondary authorization gate. This bypasses the standard WordPress security model where such requests would typically be intercepted and validated for user roles and privileges prior to object instantiation or retrieval.\nThe exposure is network-wide, provided the target site is reachable, and requires no specific privilege levels, making it highly attractive for automated exploitation scripts."
}