CVE-2026-92245
Received Received - Intake

Sensitive Information Exposure in Simply Schedule Appointments WordPress Plugin

Vulnerability report for CVE-2026-92245, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII β€” including names, email addresses, phone numbers, and custom form field data β€” stored in appointment records, as well as per-appointment public_token values. The leaked per-appointment public_token values also enable unauthenticated attackers to delete arbitrary appointments via the DELETE /wp-json/ssa/v1/appointments/{id} endpoint, which accepts the token as sole authorization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simply_schedule_appointments simply_schedule_appointments to 1.6.12.32 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Simply Schedule Appointments WordPress plugin up to version 1.6.12.32 has a flaw where the 'recursive' parameter exposes sensitive customer data. Unauthenticated attackers can access personally identifiable information like names, emails, phone numbers, and custom form data from appointment records. They can also retrieve per-appointment public tokens, which allow deleting any appointment without authentication.

Detection Guidance

Check WordPress sites running the Simply Schedule Appointments plugin for versions up to 1.6.12.32. Look for unauthorized access to endpoints like /wp-json/ssa/v1/appointments/{id} with the 'recursive' parameter. Monitor for unusual data exfiltration or appointment deletions.

Impact Analysis

If you use this plugin, attackers could steal customer data including PII and delete appointments. This risks privacy breaches, reputational damage, and operational disruption for businesses relying on the plugin for scheduling.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized exposure of personal data and HIPAA if healthcare-related PII is involved. It enables data breaches that could result in regulatory fines and legal consequences for non-compliance with data protection requirements.

Mitigation Strategies

Update the Simply Schedule Appointments plugin to the latest version immediately. If an update is unavailable, consider disabling the plugin temporarily. Review server logs for signs of exploitation and restrict access to sensitive endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92245. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart