Simply Schedule Appointments
simply-schedule-appointments · плагин
Известные уязвимости для Simply Schedule Appointments. Узнайте за секунды, какая версия работает на вашем сайте, с WP Lens.
36 известных уязвимостей
2 критичных · последняя 1 окт. 2026 г.
Уязвимости
- Критич. 9.3
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability
- Критич. 9.3
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
- Высокий 8.8
WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability
- Высокий 8.8
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode
- Высокий 8.5
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
- Высокий 7.5
Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recu
- Высокий 7.5
Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
- Высокий 7.5
CVE-2026-42384→ 1.6.11.2
WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability
- Высокий 7.5
Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
- Высокий 7.5
Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter
- Высокий 7.5
Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint
- Высокий 7.5
Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
- Высокий 7.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution
- Высокий 7.2
CVE-2023-50851→ 1.6.6.1
WordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL Injection
- Высокий 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability
- Высокий 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability
- Высокий 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability
- Высокий 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.6.20 - Reflected Cross Site Scripting (XSS) vulnerability
- Средний 6.5
Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group
- Средний 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability
- Средний 6.5
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensi
- Средний 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
- Средний 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
- Средний 6.5
Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion
- Средний 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.9.15 - Broken Access Control vulnerability
- Средний 6.5
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection
- Средний 6.4
Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
- Средний 6.1
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting
- Средний 5.4
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Средний 5.3
WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability
- Средний 5.3
Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint
- Средний 5.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service
- Средний 5.3
WordPress Simply Schedule Appointments plugin <= 1.6.10.2 - Broken Access Control vulnerability
- Средний 5.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure
- Средний 4.7
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.6.20 - Cross-Site Request Forgery to Plugin Data Reset
- Средний 4.3
Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure