Insecure Direct Object Reference in Appointment Booking Plugin for WordPress
CVE-2026-13358
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-13358?
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is prone to an Insecure Direct Object Reference vulnerability. This flaw allows authenticated users with contributor-level access or higher to exploit the ssa_past_appointments functionality, which lacks proper validation on user-controlled keys. Attackers can potentially access appointment records belonging to any user and extract sensitive information such as personal identifiable information (PII), including names, emails, phone numbers, and private notes. The vulnerability arises from the unregulated access to the /wp-json/ssa/v1/render-shortcode REST endpoint, which does not enforce adequate permission checks, exposing the appointments to unauthorized modifications.
Affected Version(s)
Simply Schedule Appointments 0 <= 1.6.12.10