CVE-2026-3045Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users through the public `/wp-json/ssa/v1/embed-inner` REST endpoint, and (2) the `get_item()` method in `SSA_Settings_Api` relies on `nonce_permissions_check()` for authorization (which accepts the public nonce) but does not call `remove_unauthorized_settings_for_current_user()` to filter restricted fields. This makes it possible for unauthenticated attackers to access admin-only plugin settings including the administrator email, phone number, internal access tokens, notification configurations, and developer settings via the `/wp-json/ssa/v1/settings/{section}` endpoint. The exposure of appointment tokens also allows an attacker to modify or cancel appointments.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-13); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-13: 3Mentions · 2026-03-14: 2Patch / Workaround · 2026-03-14: 1Technical Details · 2026-03-13: 203-1303-14
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-133
Disclosure2General1
2026-03-142
General1Patch1
Full discourse5 posts
  • EdgeDetectOps@EdgeDetectOps
    Patch

    A WordPress plugin developer sits at their laptop at 3 AM, pushing out an emergency patch for Simply Schedule Appointments. The vulnerability report just hit CVE-2026-3045. On the other side of the world, someone else is already writing code.

    Post summary

    A developer released an emergency patch for CVE‑2026‑3045 while another actor is reportedly developing code that could target the weakness, but no concrete PoC or active exploitation details are provided.

    100006
    14 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3045 The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and in… https://www.cve.org/CVERecord?id=CVE-2026-3045 ----- Traducción: CVE-2026-3045 El … http://infoflow.cloud`

    Post summary

    The tweet announces the newly published CVE-2026-3045, which exposes unauthorized sensitive data access in the Simply Schedule Appointments plugin, but offers no proof‑of‑concept, exploit evidence, or remediation details.

    1000027
    57 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-3045 - croixhaug - Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin - https://www.redpacketsecurity.com/cve-alert-cve-2026-3045-croixhaug-appointment-booking-calendar-simply-schedule-appointments-booking-plugin/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3045 #croixhaug #appointment-booking-calendar-simply-schedule-appointments-booking-plugin

    Post summary

    A tweet posts a link to a CVE alert for CVE‑2026‑3045 affecting the Simply Schedule Appointments Booking Plugin, but provides no further details on exploitation, patching, or technical specifics.

    00000107
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3045 The Appointment Booking Calendar — Simply Schedule Appointments plugin fo... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3045 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet cites CVE‑2026‑3045 for a WordPress plugin and links to vulnerability detail pages, but provides no further technical information, exploits, or remediation details.

    0000036
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3045 The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and in… https://www.cve.org/CVERecord?id=CVE-2026-3045

    Post summary

    The post announces CVE-2026-3045, stating that the Appointment Booking Calendar plugin allows unauthorized access to sensitive data across all affected versions.

    00000267
    56.7K followersView on X

Explore more