The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Simply Schedule Appointments WordPress plugin contains a Local File Inclusion (LFI) vulnerability in the 'ssa_locale' parameter that allows authenticated subscribers and above to include and execute arbitrary PHP files on the server. This is a critical risk because WordPress sites often host sensitive business data, customer information, and serve as entry points to broader infrastructure. While the vulnerability requires authentication, the low privilege threshold (subscriber level) significantly expands the attack surface—any user who can register or has been granted basic access can exploit it. Organizations using this popular appointment scheduling plugin are immediately affected across all versions through 1.6.12.27, making this a widespread exposure affecting countless small businesses, healthcare providers, and service-based companies relying on WordPress.
Casky's security skills leverage Claude AI's extended reasoning to detect the behavioral patterns and code analysis indicators associated with LFI exploitation, even though this CVE hasn't yet mapped to specific MITRE ATT&CK techniques. A practitioner monitoring their environment through Casky would identify suspicious patterns including: unusual file access requests containing path traversal sequences (../ or encoded variants), unexpected PHP execution from non-standard directories, parameter tampering on appointment scheduling endpoints, and privilege escalation indicators where subscriber accounts trigger server-side file operations. The platform would correlate these observations against 754 mapped security skills to surface attack chains—such as Initial Access (T1199: Trusted Relationship), Execution (T1059: Command and Scripting Interpreter), and Defense Evasion techniques—providing practitioners with actionable intelligence about how attackers typically chain LFI vulnerabilities into persistent code execution and lateral movement.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-89294. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation