CVE-2026-13358
A vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress, specifically in versions up to 1.6.12.10, due to inadequate validation of a user-controlled key. This allows authenticated attackers with contributor-level access or higher to access and manipulate appointment records belonging to arbitrary users, potentially revealing sensitive customer information. By exploiting this vulnerability, an attacker can obtain ownership tokens for appointments, which can be used to read or modify those appointments without further authentication.
Based on public CVE data (MITRE/NVD).