Vulnerability in Simply Schedule Appointments — CVE-2026-91109
What to do now
Update Simply Schedule Appointments to 1.6.12.33 or later.
Affected versions
- Everything up to and including 1.6.12.31
Affected: Simply Schedule Appointments (plugin, simply-schedule-appointments)
What the vulnerability is
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose every co-booker's private per-appointment id_token (exposed as public_token) alongside their PII (name and email address), then use each leaked token to read, overwrite arbitrary appointment meta on, or cancel the co-booker's appointment via the same REST controller. Exploitation requires the attacker to possess a valid id_token for any single appointment within the targeted group booking.