Missing Authorization Flaw in Appointment Booking Calendar Plugin for WordPress
CVE-2026-4807

6.5MEDIUM

What is CVE-2026-4807?

The Appointment Booking Calendar plugin for WordPress has a significant vulnerability that allows unauthenticated users to manipulate appointment data. This issue arises from flawed authorization logic in the nonce_permissions_check() method and the exposure of a site-wide reusable nonce. The /wp-json/ssa/v1/embed-inner endpoint exposes a public_nonce, which, combined with inadequate permission checks in the appointment deletion endpoints, permits attackers to view and delete arbitrary appointments. This flaw leads to the potential disclosure of sensitive appointment data, disruption of services, and loss of booking records.

Affected Version(s)

Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin 0 <= 1.6.10.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.