The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment public_token values.
The Simply Schedule Appointments plugin for WordPress has an Insecure Direct Object Reference vulnerability in all versions up to, and including, 1.6.12.31. This allows authenticated attackers with subscriber-level access and above to disclose co-bookers' private per-appointment id_tokens and PII, then use these tokens to read, overwrite, or cancel appointments.
A Missing Authorization vulnerability in the Simply Schedule Appointments Booking Plugin for WordPress allows unauthenticated attackers to modify arbitrary appointment records and expose customer PII via the bulk appointments REST API endpoint. The vulnerability exists because the plugin fails to properly verify user authorization, and relies on a static, user-independent nonce value that is exposed in th [truncated]
A time-based blind SQL injection vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress. The flaw resides in the 'append_where_sql' parameter, which lacks proper escaping and query preparation. Unauthenticated attackers can exploit this via the /appointments/bulk REST endpoint by using a publicly visible nonce embedded in the booking widget's frontend JavaScript. The attack [truncated]
A denial-of-service vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress. The plugin exposes a REST API endpoint at `/wp-json/ssa/v1/async` that accepts a user-supplied delay parameter and passes it directly to PHP's `sleep()` function without rate limiting or authentication requirements. Unauthenticated attackers can exploit this to hold PHP worker processes open for exte [truncated]