CVE · Medium

CVE-2026-13358 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13358 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 Authorization Bypass Through User-Controlled Key Medium 6.5 < 1.6.12.11 1.6.12.11 2026-08-15

CVE-2026-13358

A vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress, specifically in versions up to 1.6.12.10, due to inadequate validation of a user-controlled key. This allows authenticated attackers with contributor-level access or higher to access and manipulate appointment records belonging to arbitrary users, potentially revealing sensitive customer information. By exploiting this vulnerability, an attacker can obtain ownership tokens for appointments, which can be used to read or modify those appointments without further authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.