CVE-2026-91109

CVE-2026-91109 published: The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it poss...

View full NVD advisory → ← Back to CVE watch