Insecure Direct Object Reference in Simply Schedule Appointments Plugin for WordPress
CVE-2026-91109
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-91109?
The Simply Schedule Appointments plugin for WordPress is compromised by an Insecure Direct Object Reference vulnerability that allows authenticated users with subscriber-level access or higher to exploit the 'complete_group' parameter. Due to inadequate validation of user-controlled keys, attackers can disclose sensitive per-appointment information including private identifiers and personally identifiable information (PII) such as names and email addresses. This exploitation enables them to manipulate appointment metadata or cancel appointments through the REST controller, assuming they possess a valid appointment id_token for a targeted group booking.
Affected Version(s)
Simply Schedule Appointments 0 <= 1.6.12.31