CVE-2026-91109
Received Received - Intake

Insecure Direct Object Reference in Simply Schedule Appointments WordPress Plugin

Vulnerability report for CVE-2026-91109, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose every co-booker's private per-appointment id_token (exposed as public_token) alongside their PII (name and email address), then use each leaked token to read, overwrite arbitrary appointment meta on, or cancel the co-booker's appointment via the same REST controller. Exploitation requires the attacker to possess a valid id_token for any single appointment within the targeted group booking.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simply_schedule_appointments simply_schedule_appointments to 1.6.12.31 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the Simply Schedule Appointments WordPress plugin. It allows authenticated attackers with subscriber-level access or higher to access private per-appointment tokens and personally identifiable information (PII) of other users in the same group booking. The flaw exists due to missing validation on the 'complete_group' parameter.

Detection Guidance

To detect this vulnerability, check WordPress sites running the Simply Schedule Appointments plugin versions up to 1.6.12.31. Look for unauthorized access to appointment data or PII leaks via the 'complete_group' parameter in REST API requests. Monitor logs for suspicious REST controller activity involving id_token or public_token exposure.

Impact Analysis

If you use the Simply Schedule Appointments plugin, an attacker could exploit this to view your private appointment tokens, name, and email address. They could also cancel or modify your appointments by overwriting metadata using the leaked tokens.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's privacy rules. Exposure of PII without consent may result in compliance breaches and legal consequences.

Mitigation Strategies

Update the Simply Schedule Appointments plugin to the latest version beyond 1.6.12.31 to address the insecure direct object reference vulnerability. Ensure only trusted users have subscriber-level access or higher. Review appointment data for unauthorized changes or cancellations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91109. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart