CVE · Medium

CVE-2026-6937 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6937 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.9 Missing Authorization Medium 5.3 < 1.6.11.9 1.6.11.9 2026-05-27

CVE-2026-6937

A vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress, affecting all versions up to 1.6.11.8. The plugin fails to properly verify user authorization when accessing the bulk appointments REST API endpoint, allowing unauthenticated attackers to modify sensitive appointment information and expose customer personal data. This is due in part to the plugin's use of a static, user-independent public nonce that can be obtained by any visitor to a page hosting the plugin, enabling them to target any appointment in the system without authentication. As a result, attackers can manipulate appointment records, including customer data and payment status, and even retrieve full customer personal information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.