Skip to content
Noroxi

Simply Schedule Appointments

simply-schedule-appointments · plugin

Known security vulnerabilities for Simply Schedule Appointments. Find out in seconds which version runs on your site with WP Lens.

36 known vulnerabilities

2 critical · 26 exploitable without logging in · latest Oct 1, 2026

Listed on wordpress.org · latest 1.6.12.33 · last updated Sep 23, 2026 · 50K+ installs

wordpress.org status checked on Oct 5, 2026

Vulnerabilities

  • CVE-2026-65508unauthenticated≤ 1.6.12.10

    WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2026-39493unauthenticated≤ 1.6.9.27

    WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2026-84764unauthenticated · needs a click≤ 1.6.12.23

    WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2024-2342contributor+≤ 1.6.7.7

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode

    High 8.8
  • CVE-2026-39495login required≤ 1.6.9.27

    WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability

    High 8.5
  • CVE-2026-92245unauthenticated≤ 1.6.12.32

    Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recu

    High 7.5
  • CVE-2026-42384unauthenticated→ 1.6.11.2

    WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability

    High 7.5
  • CVE-2026-7797unauthenticated≤ 1.6.11.8

    Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter

    High 7.5
  • CVE-2026-3658unauthenticated≤ 1.6.10.0

    Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter

    High 7.5
  • CVE-2026-3045unauthenticated≤ 1.6.9.29

    Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint

    High 7.5
  • CVE-2026-1708unauthenticated≤ 1.6.9.27

    Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter

    High 7.5
  • CVE-2026-89294subscriber+≤ 1.6.12.27

    Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter

    High 7.5
  • CVE-2025-1119unauthenticated≤ 1.6.8.5

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution

    High 7.3
  • CVE-2023-50851high privilege→ 1.6.6.1

    WordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL Injection

    High 7.2
  • CVE-2026-65513unauthenticated · needs a click≤ 1.6.12.10

    WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-57317unauthenticated · needs a click≤ 1.6.12.2

    WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-39447unauthenticated · needs a click≤ 1.6.10.6

    WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2024-22311unauthenticated · needs a click≤ 1.6.6.20

    WordPress Simply Schedule Appointments plugin <= 1.6.6.20 - Reflected Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-94074unauthenticated≤ 1.6.12.29

    WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-59523unauthenticated≤ 1.6.11.11

    WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-57812unauthenticated≤ 1.6.12.4

    WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-4807unauthenticated≤ 1.6.10.6

    Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion

    Medium 6.5
  • CVE-2025-69315unauthenticated≤ 1.6.9.15

    WordPress Simply Schedule Appointments plugin <= 1.6.9.15 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-91109subscriber+≤ 1.6.12.31

    Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group

    Medium 6.5
  • CVE-2024-2341subscriber+≤ 1.6.7.7

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection

    Medium 6.5
  • CVE-2026-13358contributor+≤ 1.6.12.10

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensi

    Medium 6.5
  • CVE-2025-4667contributor+≤ 1.6.8.30

    Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes

    Medium 6.4
  • CVE-2024-13431unauthenticated · needs a click≤ 1.6.8.3

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting

    Medium 6.1
  • CVE-2024-4288contributor+≤ 1.6.7.14

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2026-94673unauthenticated≤ 1.6.12.31

    WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability

    Medium 5.3
  • CVE-2026-6937unauthenticated≤ 1.6.11.8

    Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint

    Medium 5.3
  • CVE-2026-7493unauthenticated≤ 1.6.11.5

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service

    Medium 5.3
  • CVE-2026-39694unauthenticated≤ 1.6.10.2

    WordPress Simply Schedule Appointments plugin <= 1.6.10.2 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2025-13754unauthenticated≤ 1.6.9.16

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure

    Medium 5.3
  • CVE-2024-1760unauthenticated · needs a click≤ 1.6.6.20

    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.6.20 - Cross-Site Request Forgery to Plugin Data Reset

    Medium 4.7
  • CVE-2026-1704login required≤ 1.6.9.29

    Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory