Missing Authorization Flaw in Appointment Booking Calendar Plugin for WordPress
CVE-2026-4807
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2026
What is CVE-2026-4807?
The Appointment Booking Calendar plugin for WordPress has a significant vulnerability that allows unauthenticated users to manipulate appointment data. This issue arises from flawed authorization logic in the nonce_permissions_check() method and the exposure of a site-wide reusable nonce. The /wp-json/ssa/v1/embed-inner endpoint exposes a public_nonce, which, combined with inadequate permission checks in the appointment deletion endpoints, permits attackers to view and delete arbitrary appointments. This flaw leads to the potential disclosure of sensitive appointment data, disruption of services, and loss of booking records.
Affected Version(s)
Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin 0 <= 1.6.10.6