Simply Schedule Appointments
simply-schedule-appointments · eklenti
Simply Schedule Appointments için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
36 bilinen açık
2 kritik · son kayıt 1 Eki 2026
Güvenlik açıkları
- Kritik 9.3
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability
- Kritik 9.3
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
- Yüksek 8.8
WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability
- Yüksek 8.8
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode
- Yüksek 8.5
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
- Yüksek 7.5
Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recu
- Yüksek 7.5
Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
- Yüksek 7.5
CVE-2026-42384→ 1.6.11.2
WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability
- Yüksek 7.5
Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
- Yüksek 7.5
Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter
- Yüksek 7.5
Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint
- Yüksek 7.5
Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
- Yüksek 7.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution
- Yüksek 7.2
CVE-2023-50851→ 1.6.6.1
WordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL Injection
- Yüksek 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress Simply Schedule Appointments plugin <= 1.6.6.20 - Reflected Cross Site Scripting (XSS) vulnerability
- Orta 6.5
Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group
- Orta 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability
- Orta 6.5
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensi
- Orta 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
- Orta 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
- Orta 6.5
Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion
- Orta 6.5
WordPress Simply Schedule Appointments plugin <= 1.6.9.15 - Broken Access Control vulnerability
- Orta 6.5
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection
- Orta 6.4
Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
- Orta 6.1
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting
- Orta 5.4
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Orta 5.3
WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability
- Orta 5.3
Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint
- Orta 5.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service
- Orta 5.3
WordPress Simply Schedule Appointments plugin <= 1.6.10.2 - Broken Access Control vulnerability
- Orta 5.3
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure
- Orta 4.7
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.6.20 - Cross-Site Request Forgery to Plugin Data Reset
- Orta 4.3
Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure