Security Alert Summary
The Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin for WordPress contains an insecure direct object reference that can expose appointment records and per-appointment ownership tokens. Authenticated users with Contributor-level access or higher can trigger the issue and obtain 32-character ownership tokens from rendered HTML, which may then be used without authentication to read or modify appointment data including customer PII.
CVE Details
- CVE ID: CVE-2026-13358
- Affected plugin: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin (Simply Schedule Appointments)
- Affected versions: All versions up to and including 1.6.12.10
- Published: August 16, 2026 at 5:16:46 AM UTC
- Last modified: August 16, 2026 at 5:16:46 AM UTC
- CVSS v3.1: Base Score 6.5 | MEDIUM
Vector:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low (Contributor-level is sufficient)
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
- Authentication / Permissions: Requires an authenticated account with the ability to edit posts (the plugin checks
current_user_can('edit_posts')), which maps to Contributor-level access and above on typical WordPress sites. - Weakness: CWE-639 (Insecure Direct Object Reference)
Technical Details
The plugin exposes an insecure direct object reference via the ssa_past_appointments key that is controlled by user input and not validated. Appointment records rendered by the plugin include per-appointment ownership tokens (32-character hashes) in the HTML. These tokens can be harvested by an authenticated user with contributor-level privileges.
The REST endpoint /wp-json/ssa/v1/render-shortcode is registered unconditionally on rest_api_init, regardless of the Divi theme being present. Its permission callback only requires current_user_can('edit_posts'). Because the endpoint and the uncontrolled key allow an attacker to obtain ownership tokens and interact with appointment records, harvested tokens can be used without further authentication to read or modify appointments, including customer PII (name, email, phone number, and private notes).
This issue exists because of missing validation on a user-controlled key and insufficient permission checks for the REST endpoint. The impact is limited to the appointment data managed by the plugin and does not, based on the provided data, imply broader compromise of WordPress core or unrelated plugins.
How This Could Impact Your Website
Consider a site with a site owner, internal staff who manage content, and external contractors who contribute posts or manage appointments. A contributor account used for content or scheduling could be leveraged to access appointment listings and harvest ownership tokens embedded in rendered pages. An attacker with such access could read or modify individual appointments, exposing customer PII (names, emails, phone numbers, private notes) to unauthorized parties.
Practical consequences include exposure of internal user email addresses and customer contact details, which increases the risk of targeted phishing or social engineering against staff or customers. This is particularly concerning for businesses that handle sensitive customer information as part of scheduling and appointments.
If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review your setup.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially Contributor accounts and other low-privilege accounts that can edit posts.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins and review shortcode usage that may expose sensitive data.
- Monitor site activity and access logs for unusual behavior related to the plugin or REST endpoint access patterns.
If you’d like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.
References
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.11.0/includes/class-appointment-model.php#L1936
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.11.0/includes/class-db-model.php#L325
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.11.0/includes/class-divi.php#L237
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.11.0/includes/class-divi.php#L254
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.11.0/includes/class-shortcodes.php#L781
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.4/includes/class-appointment-model.php#L1936
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.4/includes/class-db-model.php#L325
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.4/includes/class-divi.php#L237
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.4/includes/class-divi.php#L254
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.4/includes/class-shortcodes.php#L781
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3617759%40simply-schedule-appointments&new=3617759%40simply-schedule-appointments
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5dbe5094-d255-46b1-9e8e-9c48cd74e8a2?source=cve