CVE-2026-91109 | croixhaug Simply Schedule Appointments Plugin up to 1.6.12.31 on WordPress REST Controller complete_group authorization
A vulnerability categorized as critical has been discovered in croixhaug Simply Schedule Appointments Plugin up to 1.6.12.31 on WordPress. This impacts an unknown function of the component REST Controller. The manipulation of the argument complete_group results in authorization bypass.
This vulnerability is identified as CVE-2026-91109. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More