
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1704 is an Insecure Direct Object Reference (IDOR) vulnerability in the "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin" for WordPress. It affects all versions up to and including 1.6.9.29, allowing authenticated attackers with the ssa_manage_appointments capability (e.g., Team Members) to access appointment records belonging to other staff members and expose sensitive customer PII. The vulnerability was published on March 13, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is an authorization bypass through a user-controlled key (CWE-639). Specifically, the get_item_permissions_check method in class-appointment-model.php grants access to any user holding the ssa_manage_appointments capability without verifying that the requesting user is the staff member who owns the appointment. An authenticated attacker can manipulate the appointment ID parameter in API requests to retrieve appointment records they do not own, exposing customer PII such as names, contact details, and scheduling information (Wordfence, WordPress Trac).
Successful exploitation allows authenticated low-privileged users (Team Members or any user granted ssa_manage_appointments) to read appointment records belonging to other staff members, including sensitive customer personally identifiable information (PII) such as names, email addresses, and phone numbers. The impact is limited to confidentiality — there is no integrity or availability impact — and exploitation requires an existing account on the WordPress site. Lateral movement beyond the WordPress application is not directly facilitated by this vulnerability (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported. The EPSS score is approximately 0.024% (0.000240), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Wordfence).
ssa_manage_appointments capability (e.g., a Team Member role).get_item_permissions_check method will incorrectly grant access, returning the full appointment record including customer PII./wp-json/ssa/v1/appointments/<id>) from a Team Member account accessing IDs outside their normal scope.ssa_manage_appointments user account accessing a high volume of appointment records in a short time period, particularly records not associated with their staff profile.Users should update the Simply Schedule Appointments plugin to a version beyond 1.6.9.29, which includes the fix applied in the changeset that corrects the get_item_permissions_check method to validate staff ownership of appointments. The patch is available via the WordPress plugin repository. As a temporary workaround, site administrators can restrict the ssa_manage_appointments capability to only fully trusted users until the update is applied (Wordfence, WordPress Trac Changeset).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for March 9–15, 2026, and Sucuri included it in their March 2026 vulnerability patch roundup. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregation (Wordfence Blog, Sucuri Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."