CVE-2026-6723 PUBLISHED

Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token

Assigner: Wordfence
Reserved: 20.04.2026 Published: 10.10.2026 Updated: 10.10.2026

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor croixhaug
Product Simply Schedule Appointments
Versions Default: unaffected
  • affected from 0 to 1.6.11.11 (incl.)

Credits

  • awhacken finder

References

Problem Types

  • CWE-863 Incorrect Authorization CWE