The Appointment Booking Calendar — Simply Schedule...
Moderate severity
Unreviewed
Published
Oct 10, 2026
to the GitHub Advisory Database
•
Updated Oct 10, 2026
Description
Published by the National Vulnerability Database
Oct 10, 2026
Published to the GitHub Advisory Database
Oct 10, 2026
Last updated
Oct 10, 2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.
References