S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2373 Scanner

CVE-2022-2373 scanner - Information Disclosure vulnerability in Simply Schedule Appointments plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2373
5.3
CVSS

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Simply Schedule Appointments – WordPress Booking Plugin
AFFECTED< 1.5.7.7SAFE ✓≥ 1.5.7.7
Updated Aug 22, 2026View on NVD →
Detail

Simply Schedule Appointments (SSA) is a popular WordPress plugin designed for appointment scheduling. The plugin provides a user-friendly interface and allows businesses in numerous industries to integrate appointment booking facilities into their website. SSA enables business owners to streamline appointment bookings, send automated reminders to clients, and manage customer data efficiently. Moreover, SSA offers personalised booking forms and customisable email templates that help to improve business branding and user engagement.

According to security researchers, SSA before version 1.5.7.7 had a critical vulnerability - CVE-2022-2373. This exploit allows unauthorised users to access WordPress users’ sensitive information, such as personal details and confidential data. This vulnerability is the result of a flaw in the application's REST endpoint, which did not have the necessary authentication to prevent unauthorised access. As a result, cybercriminals could easily exploit this vulnerability, using various approaches to steal sensitive personal data from SSA users.

Exploiting this vulnerability could lead to a significant data breach, resulting in financial loss and damage to a business's reputation. Cybercriminals could use the stolen data for identity theft and fraud, taking control of sensitive details, compromising the security of customer information and potentially exposing the business to significant legal liabilities. Customers could lose faith and trust in the business, leading to a decline in revenue and reputation damage.

Businesses need to prioritise the protection of their digital assets. Using advanced security features provided by the s4e.io platform can help businesses quickly identify and address vulnerabilities in their digital assets. Features such as daily security scans, vulnerability assessments, and threat monitoring ensure businesses remain ahead of cybercriminals' evolving tactics. By leveraging these security features, businesses can have peace of mind knowing their digital assets are protected, and customers’ sensitive data remains secure.

 

REFERENCES

Solution Advice

Businesses using SSA are highly encouraged to take the following precautions to protect against this vulnerability:

  • Update the application to the latest version, which contains the necessary security patches to fix this vulnerability.
  • Deploy endpoint request authorisation, such as implementing User Role Access Control (URAC), to prevent unauthorised access.
  • Utilise firewalls and intrusion detection systems (IDS) to monitor and prevent suspicious activity.
  • Employ strong and unique passwords for all user accounts and regularly change passwords.
  • Conduct regular backups of all data to ensure it is recoverable in case of a security incident.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.