Simply Schedule Appointments
simply-schedule-appointments · plugin
Known security vulnerabilities for Simply Schedule Appointments. Find out in seconds which version runs on your site with WP Lens.
36 known vulnerabilities
2 critical · 26 exploitable without logging in · latest Oct 1, 2026
Listed on wordpress.org · latest 1.6.12.33 · last updated Sep 23, 2026 · 50K+ installs
wordpress.org status checked on Oct 5, 2026
Vulnerabilities
- Critical 9.3
CVE-2026-65508unauthenticated≤ 1.6.12.10
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability
- Critical 9.3
CVE-2026-39493unauthenticated≤ 1.6.9.27
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
- High 8.8
CVE-2026-84764unauthenticated · needs a click≤ 1.6.12.23
WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability
- High 8.8
CVE-2024-2342contributor+≤ 1.6.7.7
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode
- High 8.5
CVE-2026-39495login required≤ 1.6.9.27
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
- High 7.5
CVE-2026-92245unauthenticated≤ 1.6.12.32
Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recu
- High 7.5
CVE-2026-42384unauthenticated→ 1.6.11.2
WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability
- High 7.5
CVE-2026-7797unauthenticated≤ 1.6.11.8
Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
- High 7.5
CVE-2026-3658unauthenticated≤ 1.6.10.0
Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter
- High 7.5
CVE-2026-3045unauthenticated≤ 1.6.9.29
Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint
- High 7.5
CVE-2026-1708unauthenticated≤ 1.6.9.27
Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
- High 7.5
CVE-2026-89294subscriber+≤ 1.6.12.27
Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
- High 7.3
CVE-2025-1119unauthenticated≤ 1.6.8.5
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution
- High 7.2
CVE-2023-50851high privilege→ 1.6.6.1
WordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL Injection
- High 7.1
CVE-2026-65513unauthenticated · needs a click≤ 1.6.12.10
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-57317unauthenticated · needs a click≤ 1.6.12.2
WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-39447unauthenticated · needs a click≤ 1.6.10.6
WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2024-22311unauthenticated · needs a click≤ 1.6.6.20
WordPress Simply Schedule Appointments plugin <= 1.6.6.20 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-94074unauthenticated≤ 1.6.12.29
WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability
- Medium 6.5
CVE-2026-59523unauthenticated≤ 1.6.11.11
WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
- Medium 6.5
CVE-2026-57812unauthenticated≤ 1.6.12.4
WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
- Medium 6.5
CVE-2026-4807unauthenticated≤ 1.6.10.6
Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion
- Medium 6.5
CVE-2025-69315unauthenticated≤ 1.6.9.15
WordPress Simply Schedule Appointments plugin <= 1.6.9.15 - Broken Access Control vulnerability
- Medium 6.5
CVE-2026-91109subscriber+≤ 1.6.12.31
Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group
- Medium 6.5
CVE-2024-2341subscriber+≤ 1.6.7.7
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection
- Medium 6.5
CVE-2026-13358contributor+≤ 1.6.12.10
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensi
- Medium 6.4
CVE-2025-4667contributor+≤ 1.6.8.30
Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
- Medium 6.1
CVE-2024-13431unauthenticated · needs a click≤ 1.6.8.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting
- Medium 5.4
CVE-2024-4288contributor+≤ 1.6.7.14
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.3
CVE-2026-94673unauthenticated≤ 1.6.12.31
WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability
- Medium 5.3
CVE-2026-6937unauthenticated≤ 1.6.11.8
Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint
- Medium 5.3
CVE-2026-7493unauthenticated≤ 1.6.11.5
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service
- Medium 5.3
CVE-2026-39694unauthenticated≤ 1.6.10.2
WordPress Simply Schedule Appointments plugin <= 1.6.10.2 - Broken Access Control vulnerability
- Medium 5.3
CVE-2025-13754unauthenticated≤ 1.6.9.16
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure
- Medium 4.7
CVE-2024-1760unauthenticated · needs a click≤ 1.6.6.20
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.6.20 - Cross-Site Request Forgery to Plugin Data Reset
- Medium 4.3
CVE-2026-1704login required≤ 1.6.9.29
Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).