Insecure Direct Object Reference in Simply Schedule Appointments Plugin for WordPress
CVE-2026-91109

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-91109?

The Simply Schedule Appointments plugin for WordPress is compromised by an Insecure Direct Object Reference vulnerability that allows authenticated users with subscriber-level access or higher to exploit the 'complete_group' parameter. Due to inadequate validation of user-controlled keys, attackers can disclose sensitive per-appointment information including private identifiers and personally identifiable information (PII) such as names and email addresses. This exploitation enables them to manipulate appointment metadata or cancel appointments through the REST controller, assuming they possess a valid appointment id_token for a targeted group booking.

Affected Version(s)

Simply Schedule Appointments 0 <= 1.6.12.31

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jtb75
.