→ برگشت به فید آسیبپذیریها
CVE-2026-92245 · simply-schedule-appointments
افشای اطلاعات حساس بدون احراز هویت در افزونه Simply Schedule Appointments
افزونه Simply Schedule Appointments تا نسخه ۱.۶.۱۲.۳۲ از طریق پارامتر recursive به افشای اطلاعات حساس آسیبپذیر است و مهاجمان بدون احراز هویت میتوانند اطلاعات شخصی مشتریان شامل نام، ایمیل، تلفن و فیلدهای سفارشی را به همراه توکنهای public_token استخراج کنند. این توکنها امکان حذف غیرمجاز قرار ملاقاتهای دلخواه را از طریق endpoint مربوطه فراهم کرده و منجر به نقض حریم خصوصی و اختلال در رزروها میشود. با توجه به وجود وصله امنیتی، بهروزرسانی فوری افزونه به نسخه امن ضروری است.
نسخههای تحت تأثیر
<= 1.6.12.32
راهنمای اقدام و رفع مشکل (Remediation)
- ۱. پشتیبانگیری: قبل از اعمال هرگونه تغییر، یک بکاپ کامل از پایگاه داده و فایلهای سایت تهیه کنید.
- ۲. بهروزرسانی سریع: افزونه یا هسته simply-schedule-appointments را بلافاصله به آخرین نسخه ارائهشده ارتقا دهید.
- ۳. فایروال و مانیتورینگ: در صورت عدم امکان آپدیت فوری، رولهای امنیتی WAF را فعال کرده و لاگهای وبسرور را پایش نمایید.
مراجع رسمی و مستندات
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1984f80e-06ec-4d7f-9a75-e05e7b73b57c?source=api-prod ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1984f80e-06ec-4d7f-9a75-e05e7b73b57c ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-appointment-model.php#L2310 ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-appointment-type-model.php#L961 ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-bootstrap.php#L151 ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-db-model.php#L348 ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/lib/td-util/class-td-api-model.php#L140 ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/lib/td-util/class-td-api-model.php#L387 ↗
- https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/lib/td-util/class-td-api-model.php#L510 ↗
- https://plugins.trac.wordpress.org/changeset/3709365/simply-schedule-appointments/trunk/includes/class-appointment-type-model.php ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1984f80e-06ec-4d7f-9a75-e05e7b73b57c?source=cve ↗