📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Consumer Electronics and Retail MEDIUM 1h Global supply_chain Software Development and Technology HIGH 1h Global general Artificial Intelligence and Software Development LOW 2h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h Global general Consumer Electronics and Retail MEDIUM 1h Global supply_chain Software Development and Technology HIGH 1h Global general Artificial Intelligence and Software Development LOW 2h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h Global general Consumer Electronics and Retail MEDIUM 1h Global supply_chain Software Development and Technology HIGH 1h Global general Artificial Intelligence and Software Development LOW 2h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h
Vulnerabilities

CVE-2026-4807

Medium
CWE-862 — Weakness Type
Published: May 7, 2026  ·  Modified: May 9, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce value through the /wp-json/ssa/v1/embed-inner endpoint, which is accessible to unauthenticated users. The appointment deletion endpoint at /wp-json/ssa/v1/appointments/{id}/delete and /wp-json/ssa/v1/appointments/bulk use a permission check that accepts requests containing both an X-WP-Nonce header (with any arbitrary value) and an X-PUBLIC-Nonce header (with the valid public nonce). When the X-WP-Nonce validation fails, the function falls back to validating the X-PUBLIC-Nonce without properly rejecting the request. Since the public_nonce is exposed to all unauthenticated visitors and is site-wide (not user-specific or appointment-specific), attackers can obtain it and use it to view details of arbitrary appointments, including the public_edit_url, or delete arbitrary appointments by ID. This makes it possible for unauthenticated attackers to view, delete or modify any appointment in the system, disclosing sensitive appointment data, causing service disruption, and loss of booking records.

🤖 AI Executive Summary

The Appointment Booking Calendar WordPress plugin versions up to 1.6.10.6 contain a missing authorization vulnerability allowing unauthenticated users to delete appointments via a publicly exposed nonce. Attackers can exploit flawed authorization logic in the nonce validation to bypass security checks and perform unauthorized appointment deletions.

📄 Description (Arabic)

تحتوي إضافة Appointment Booking Calendar للـ WordPress على خلل في منطق التفويض حيث يتم الكشف عن nonce عام يمكن الوصول إليه من قبل المستخدمين غير المصرح لهم. يمكن للمهاجمين استخدام هذا الـ nonce العام للتحايل على فحوصات التحقق وحذف المواعيد بشكل غير مصرح به من خلال نقاط نهاية REST API. الثغرة تؤثر على الإصدارات حتى 1.6.10.6 وتتطلب تحديثاً فورياً.

🤖 ملخص تنفيذي (AI)

The Appointment Booking Calendar WordPress plugin versions up to 1.6.10.6 contain a missing authorization vulnerability allowing unauthenticated users to delete appointments via a publicly exposed nonce. Attackers can exploit flawed authorization logic in the nonce validation to bypass security checks and perform unauthorized appointment deletions.

🤖 AI Intelligence Analysis Analyzed: May 11, 2026 16:26
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
healthcare government telecom
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
6.0
/ 10.0
🔧 Remediation Steps (English)
Update the Appointment Booking Calendar plugin to version 1.6.10.7 or later immediately. Implement proper authorization checks that do not rely solely on nonce validation. Restrict access to the /wp-json/ssa/v1/embed-inner endpoint and ensure all appointment deletion endpoints require authenticated user sessions with proper capability checks.
🔧 خطوات المعالجة (العربية)
قم بتحديث إضافة Appointment Booking Calendar إلى الإصدار 1.6.10.7 أو أحدث فوراً. قم بتنفيذ فحوصات تفويض مناسبة لا تعتمد على التحقق من nonce وحده. قيد الوصول إلى نقطة النهاية /wp-json/ssa/v1/embed-inner وتأكد من أن جميع نقاط نهاية حذف المواعيد تتطلب جلسات مستخدم مصرح بها مع فحوصات القدرات المناسبة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1
🔵 SAMA CSF
AC-2 AC-3 SI-10
🟡 ISO 27001:2022
A.9.2.1 A.9.2.5 A.14.2.1
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-862
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-05-07
Source Feed nvd
🇸🇦 Saudi Risk Score
6.0
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-862
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.