CVE-2026-6723: Croixhaug Simply Schedule Appointments

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.

Affected products

  • Croixhaug Simply Schedule Appointments: up to and including 1.6.11.11

Published 2026-10-10. Last modified 2026-10-10.