---
id: CVE-2026-6723
title: >-
  The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
  plugin for WordPress is vulnerable to Incorrect Authorization in all versions
  up to, and including, 1.6.11.11
summary: >-
  The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
  plugin for WordPress is vulnerable to Incorrect Authorization in all versions
  up to, and including, 1.6.11.11. This is due to the appointment update REST
  API …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T05:16:40.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6723'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3562241/simply-schedule-appointments
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b6f16178-1aa3-4af2-a125-74467bc57e70?source=cve
    label: security@wordfence.com
tags:
  - nvd
ingestedAt: '2026-10-10T05:23:33.493Z'
---

## Overview

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
