CVE-2026-6723: Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs an appointment public token for a target appointment. No WordPress account or other authentication is required once the token is used.
What can be changed through the vulnerable endpoint?
An attacker can modify admin-controlled fields on the appointment, including payment confirmation status, the user assigned to the appointment, and the service type.
Which installations are affected?
Simply Schedule Appointments Appointment Booking Calendar versions up to and including 1.6.11.11 are affected.