Denial of Service Vulnerability in Appointment Booking Calendar Plugin for WordPress
CVE-2026-7493
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-7493?
The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit a publicly accessible REST API endpoint. Specifically, the endpoint (/wp-json/ssa/v1/async) calls PHP's sleep() function using a user-supplied delay without any rate limiting, enabling attackers to exhaust PHP worker processes. This denial of service can prevent legitimate users from accessing the site, posing a significant risk to website availability.
Affected Version(s)
Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin 0 <= 1.6.11.5