{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asimply_schedule_appointmentssimply_schedule_appointmentswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:simply_schedule_appointments:simply_schedule_appointments:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89294"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simply Schedule Appointments (\u003c= 1.6.12.27)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Simply Schedule Appointments"],"content_html":"\u003cp\u003eThe Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion (LFI) in all versions up to and including 1.6.12.27. The flaw originates from the 'ssa_locale' parameter, which is processed by a locale filter installed during the 'plugins_loaded' hook. Crucially, the plugin implementation fails to perform any nonce or capability validation on this parameter, processing it unconditionally on every incoming request. This design failure allows an unauthenticated remote attacker to manipulate the file inclusion path, potentially enabling the inclusion and execution of arbitrary .php files residing on the server. Successful exploitation can lead to full remote code execution, unauthorized access to sensitive application data, and the bypass of established WordPress access controls. Defenders should prioritize patching or disabling the plugin until an update is confirmed, as the lack of authentication requirements significantly lowers the barrier for exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running the vulnerable Simply Schedule Appointments plugin (\u0026lt;= 1.6.12.27).\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET or POST request targeting the site, injecting a malicious path into the 'ssa_locale' parameter.\u003c/li\u003e\n\u003cli\u003eThe 'plugins_loaded' hook fires upon the request reaching the WordPress server.\u003c/li\u003e\n\u003cli\u003eThe vulnerable filter processes the 'ssa_locale' value without authorization checks, resolving the path to a local target file.\u003c/li\u003e\n\u003cli\u003eThe server attempts to include the specified file as a PHP script.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages a previously uploaded or existing local .php file (e.g., via a separate file upload vulnerability or log injection) to achieve arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eAttacker executes system commands to exfiltrate database credentials or establish a persistent backdoor.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe threat to any WordPress installation using affected versions of Simply Schedule Appointments. Successful exploitation results in remote code execution, allowing attackers to compromise the underlying web server, steal sensitive configuration data, or gain administrative access to the WordPress environment. Given the ubiquity of WordPress plugins, this flaw represents a significant risk to organizations across all sectors that rely on this plugin for scheduling or appointment management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Simply Schedule Appointments plugin to a patched version once released by the vendor.\u003c/li\u003e\n\u003cli\u003eUntil a patch is applied, disable the Simply Schedule Appointments plugin to mitigate the risk of unauthenticated LFI.\u003c/li\u003e\n\u003cli\u003eDeploy Web Application Firewall (WAF) rules to detect and block requests containing suspicious paths or directory traversal sequences (e.g., ../, /etc/passwd) in the 'ssa_locale' parameter.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any anomalous requests involving the 'ssa_locale' parameter targeting system-level files or hidden directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T08:33:09Z","date_published":"2026-09-30T08:33:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lfi-simply-schedule-appointments/","summary":"An unauthenticated Local File Inclusion (LFI) vulnerability in the Simply Schedule Appointments WordPress plugin allows attackers to execute arbitrary PHP code.","title":"Local File Inclusion in Simply Schedule Appointments WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-lfi-simply-schedule-appointments/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:simply_schedule_appointments:simply_schedule_appointments:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}