Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type. | |
| Title | Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-10T04:26:46.386Z
Reserved: 2026-04-20T19:51:21.160Z
Link: CVE-2026-6723
No data.
Status : Received
Published: 2026-10-10T05:16:40.147
Modified: 2026-10-10T05:16:40.147
Link: CVE-2026-6723
No data.
OpenCVE Enrichment
Updated: 2026-10-10T05:30:09Z