CVE · Medium

CVE-2026-4807 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-4807 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11 Missing Authorization Medium 6.5 < 1.6.11 1.6.11 2026-05-06

CVE-2026-4807

A WordPress plugin called Appointment Booking Calendar is flawed in its permission handling mechanism, specifically within the nonce_permissions_check() method. A site-wide reusable nonce, accessible via a public endpoint, is not properly validated when used in conjunction with an arbitrary WP-Nonce header value. As a result, attackers can obtain this nonce and exploit it to view or delete any appointment on the site, compromising sensitive information and disrupting services.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.