CVE-2026-6937
A vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress, affecting all versions up to 1.6.11.8. The plugin fails to properly verify user authorization when accessing the bulk appointments REST API endpoint, allowing unauthenticated attackers to modify sensitive appointment information and expose customer personal data. This is due in part to the plugin's use of a static, user-independent public nonce that can be obtained by any visitor to a page hosting the plugin, enabling them to target any appointment in the system without authentication. As a result, attackers can manipulate appointment records, including customer data and payment status, and even retrieve full customer personal information.
Based on public CVE data (MITRE/NVD).