CVE-2026-6723
Received Received - Intake

Incorrect Authorization in Appointment Booking Calendar WordPress Plugin

Vulnerability report for CVE-2026-6723, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
croixhaug Simply Schedule Appointments 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This WordPress plugin vulnerability allows unauthenticated attackers to modify admin-controlled fields on appointments via a token-authenticated REST API endpoint. Attackers can fake payment confirmations, reassign appointments to other users, or change service types due to incorrect authorization checks.

Detection Guidance

Check WordPress installations for the Appointment Booking Calendar plugin versions up to 1.6.11.11. Review server logs for unauthorized appointment modifications or REST API calls to /wp-json/ssab/v1/appointments.

Impact Analysis

If you use this plugin, attackers could manipulate appointment data, leading to fraudulent payments, incorrect scheduling, or unauthorized changes to services. This could disrupt business operations and damage trust with customers.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data through unauthorized appointment modifications. For HIPAA, it may compromise protected health information if appointment details are altered. Compliance risks include data integrity breaches and unauthorized access.

Mitigation Strategies

Update the plugin to the latest version if available. Disable the plugin if no update is available. Restrict access to the REST API endpoint /wp-json/ssab/v1/appointments via server rules or firewall.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6723. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart