What is CVE-2026-13358?
CVE-2026-13358 is an Insecure Direct Object Reference vulnerability in the 'Simply Schedule Appointments Booking Plugin' for WordPress. It affects all versions up to 1.6.12.10 via the 'ssa_past_appointments' function due to missing user key validation, allowing unauthenticated access to appointment data. Users should update the plugin immediately.
Azərbaycanca: CVE-2026-13358, 'Simply Schedule Appointments Booking Plugin' üçün WordPress plagini üçün təhlükəsizlik boşluğudur. Bu boşluq 'ssa_past_appointments' funksiyasında istifadəçi tərəfindən idarə olunan açarda yoxlama olmaması səbəbindən, doğrulanmamış istifadəçilərə aidiyyatı olmayan görüş məlumatlarına giriş imkanı verir. Plaginin 1.6.12.10 daxil olmaqla bütün versiyaları təsirlənir, istifadəçilər dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin exactly does CVE-2026-13358 affect?
The vulnerability affects the 'Simply Schedule Appointments Booking Plugin' for WordPress.
Is authentication required to exploit this vulnerability?
No, the vulnerability allows unauthenticated access to unrelated appointment data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.