Insecure Direct Object Reference in Appointment Booking Plugin for WordPress
CVE-2026-13358

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2026

What is CVE-2026-13358?

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is prone to an Insecure Direct Object Reference vulnerability. This flaw allows authenticated users with contributor-level access or higher to exploit the ssa_past_appointments functionality, which lacks proper validation on user-controlled keys. Attackers can potentially access appointment records belonging to any user and extract sensitive information such as personal identifiable information (PII), including names, emails, phone numbers, and private notes. The vulnerability arises from the unregulated access to the /wp-json/ssa/v1/render-shortcode REST endpoint, which does not enforce adequate permission checks, exposing the appointments to unauthorized modifications.

Affected Version(s)

Simply Schedule Appointments 0 <= 1.6.12.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Iden (Mickhat)
.