CVE-2026-13358

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to access appointment records belonging to arbitrary users and harvest the per-appointment ownership tokens (32-character hashes) embedded in the rendered HTML, which can then be used without any authentication to read or modify those appointments including full customer PII such as name, email, phone number, and private notes. The /wp-json/ssa/v1/render-shortcode REST endpoint is registered unconditionally on rest_api_init regardless of whether the Divi theme is installed, and its permission callback only requires current_user_can('edit_posts'), meaning any Contributor-level account is sufficient to trigger this entire exploit chain.


We have discovered 5,775 live websites that are affected by CVE-2026-13358.

Run a Free Instant Scan




Affected Software

Product  Simply Schedule Appointments
Category Wordpress Plugins
Vulnerable Domains5,775 live websites (77% of Simply Schedule Appointments install base)
Vulnerable Versions
  • from 0 through 1.6.12.10
Vulnerable Versions Count164 versions ( 47% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Michael Iden (Mickhat) (finder)

Website Distribution by Country

Number of websites using CVE-2026-13358
United States1,602 websites



Germany1,165 websites
Italy339 websites
GB287 websites
Netherlands235 websites
France220 websites
Spain157 websites
Canada149 websites
Denmark127 websites
Switzerland110 websites

Website Distribution by TLD

Number of websites using CVE-2026-13358
.com2,304 websites
.de840 websites
.it242 websites
.nl210 websites
.org209 websites
.co.uk174 websites
.net131 websites
.fr108 websites
.ch100 websites
.ca81 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13358

Top websites that are affected by CVE-2026-13358. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.org United States**,***
*********.org United States**,***
*****************.org GB***,***
****************.org United States***,***
****.hu Hungary***,***
**************.com United States***,***
***********.com United States***,***
******.***.edu United States***,***
************.hu Hungary***,***
****.org United States***,***
See full domain list

FAQ

CVE-2026-13358 is Authorization Bypass Through User-Controlled Key in Simply Schedule Appointments
A total of 5,775 websites have been identified as vulnerable to CVE-2026-13358, based on global website indexing conducted by WebTechSurvey.
The Simply Schedule Appointments is affected by the CVE-2026-13358 vulnerability.
Simply Schedule Appointments versions up to and including 1.6.12.10 are vulnerable to CVE-2026-13358.

References