Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for authenticated...
- CVSS:
- 6.5
- Affected:
- up to 1.6.12.10
- Fixed in:
- 1.6.12.11
- Disclosed:
- Aug 15, 2026
CVE-2026-13358 on NVD →
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Insecure Direct Object Reference
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to 1.6.12.6 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.12.6
- Fixed in:
- 1.6.12.6
- Disclosed:
- Aug 6, 2026
CVE-2026-16540 on NVD →
Simply Schedule Appointments <= 1.6.12.10 - Unauthenticated SQL Injection
high
The Simply Schedule Appointments plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.12.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additi...
- CVSS:
- 7.5
- Affected:
- up to 1.6.12.10
- Fixed in:
- 1.6.12.11
- Disclosed:
- Jul 28, 2026
CVE-2026-65508 on NVD →
Simply Schedule Appointments <= 1.6.12.10 - Unauthenticated Stored Cross-Site Scripting
high
The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.12.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 1.6.12.10
- Fixed in:
- 1.6.12.11
- Disclosed:
- Jul 28, 2026
CVE-2026-65513 on NVD →
Simply Schedule Appointments <= 1.6.12.10 - Missing Authorization to Authenticated (Contributor+) Sensitive Data Disclosure
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.6.12.10. This is due to missing capability checks on user-controlled shortcode attributes in the ssa_admin_upcoming_appointments shortcode handler, allowing non-managers to bypass staff scoping...
- CVSS:
- 4.3
- Affected:
- up to 1.6.12.10
- Fixed in:
- 1.6.12.11
- Disclosed:
- Jul 23, 2026
CVE-2026-15254 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.12.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.12.4
- Fixed in:
- 1.6.12.6
- Disclosed:
- Jul 9, 2026
CVE-2026-57812 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.11.11. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.11.11
- Fixed in:
- 1.6.12.0
- Disclosed:
- Jul 9, 2026
CVE-2026-59523 on NVD →
Simply Schedule Appointments <= 1.6.12.3 - Unauthenticated Stored Cross-Site Scripting
high
The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.12.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...
- CVSS:
- 7.2
- Affected:
- up to 1.6.12.3
- Fixed in:
- 1.6.12.4
- Disclosed:
- Jul 6, 2026
CVE-2026-13400 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.2 - Unauthenticated Stored Cross-Site Scripting
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 7.2
- Affected:
- up to 1.6.12.2
- Fixed in:
- 1.6.12.4
- Disclosed:
- Jun 26, 2026
CVE-2026-57317 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.10.6 - Unauthenticated Stored Cross-Site Scripting
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 7.2
- Affected:
- up to 1.6.10.6
- Fixed in:
- 1.6.11.0
- Disclosed:
- May 28, 2026
CVE-2026-39447 on NVD →
Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint. T...
- CVSS:
- 5.3
- Affected:
- up to 1.6.11.8
- Fixed in:
- 1.6.11.9
- Disclosed:
- May 27, 2026
CVE-2026-6937 on NVD →
Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...
- CVSS:
- 7.5
- Affected:
- up to 1.6.11.8
- Fixed in:
- 1.6.11.9
- Disclosed:
- May 27, 2026
CVE-2026-7797 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied delay...
- CVSS:
- 5.3
- Affected:
- up to 1.6.11.5
- Fixed in:
- 1.6.11.7
- Disclosed:
- May 26, 2026
CVE-2026-7493 on NVD →
Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion
medium
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce va...
- CVSS:
- 6.5
- Affected:
- up to 1.6.10.6
- Fixed in:
- 1.6.11
- Disclosed:
- May 6, 2026
CVE-2026-4807 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin < 1.6.11.2 - Unauthenticated Sensitive Information Exposure
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 1.6.11.2 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.6.11.2
- Fixed in:
- 1.6.11.2
- Disclosed:
- Apr 27, 2026
CVE-2026-42384 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.27 - Unauthenticated SQL Injection
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.9.27 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...
- CVSS:
- 7.5
- Affected:
- up to 1.6.9.27
- Fixed in:
- 1.6.9.29
- Disclosed:
- Apr 8, 2026
CVE-2026-39493 on NVD →
Simply Schedule Appointments <= 1.6.9.27 - Authenticated (Contributor+) SQL Injection
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.9.27 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.5
- Affected:
- up to 1.6.9.27
- Fixed in:
- 1.6.9.29
- Disclosed:
- Mar 26, 2026
CVE-2026-39495 on NVD →
Simply Schedule Appointments - Unauthenticated SQL Injection via 'fields' Parameter vulnerability
critical
Unauthenticated SQL Injection via 'fields' Parameter vulnerability
- CVSS:
- 9.3
- Affected:
- up to 1.6.10.0
- Fixed in:
- 1.6.10.2
- Disclosed:
- Mar 20, 2026
Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
- CVSS:
- 7.5
- Affected:
- up to 1.6.10.0
- Fixed in:
- 1.6.10.2
- Disclosed:
- Mar 18, 2026
CVE-2026-3658 on NVD →
Simply Schedule Appointments - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint vulnerability
high
Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint vulnerability
- CVSS:
- 7.5
- Affected:
- up to 1.6.9.29
- Fixed in:
- 1.6.10.0
- Disclosed:
- Mar 13, 2026
Simply Schedule Appointments - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure vulnerability
medium
Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure vulnerability
- CVSS:
- 4.3
- Affected:
- up to 1.6.9.29
- Fixed in:
- 1.6.10.0
- Disclosed:
- Mar 13, 2026
Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint
high
The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users through the public...
- CVSS:
- 7.5
- Affected:
- up to 1.6.9.29
- Fixed in:
- 1.6.10.0
- Disclosed:
- Mar 12, 2026
CVE-2026-3045 on NVD →
Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments` capabil...
- CVSS:
- 4.3
- Affected:
- up to 1.6.9.29
- Fixed in:
- 1.6.10.0
- Disclosed:
- Mar 12, 2026
CVE-2026-1704 on NVD →
Simply Schedule Appointments - Unauthenticated SQL Injection via 'append_where_sql' Parameter vulnerability
critical
Unauthenticated SQL Injection via 'append_where_sql' Parameter vulnerability
- CVSS:
- 9.3
- Affected:
- up to 1.6.9.27
- Fixed in:
- 1.6.9.29
- Disclosed:
- Mar 11, 2026
Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent the `append_where_sql` parameter from bei...
- CVSS:
- 7.5
- Affected:
- up to 1.6.9.27
- Fixed in:
- 1.6.9.29
- Disclosed:
- Mar 10, 2026
CVE-2026-1708 on NVD →
Simply Schedule Appointments <= 1.6.11.0 - Missing Authorization
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.11.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.11.0
- Fixed in:
- 1.6.11.1
- Disclosed:
- Feb 26, 2026
CVE-2026-39694 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] <= 1.6.9.15 (unfixed)
unknown
[en] Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.
- Affected:
- up to 1.6.9.15
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-69315 on NVD →
Simply Schedule Appointments <= 1.6.9.15 - Missing Authorization
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.9.15. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.9.15
- Fixed in:
- 1.6.9.17
- Disclosed:
- Jan 20, 2026
CVE-2025-69315 on NVD →
Simply Schedule Appointments <= 1.6.9.9 - Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient prep...
- CVSS:
- 7.5
- Affected:
- up to 1.6.9.9
- Fixed in:
- 1.6.9.13
- Disclosed:
- Jan 14, 2026
CVE-2025-12166 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.9.13
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient...
- Affected:
- up to 1.6.9.13
- Fixed in:
- 1.6.9.13
- Disclosed:
- Jan 14, 2026
CVE-2025-12166 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.9.6
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 1.6.9.6
- Fixed in:
- 1.6.9.6
- Disclosed:
- Jan 6, 2026
CVE-2025-11723 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possible for unauthenticated attackers to gene...
- CVSS:
- 6.5
- Affected:
- up to 1.6.9.5
- Fixed in:
- 1.6.9.6
- Disclosed:
- Jan 5, 2026
CVE-2025-11723 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.9.17
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, whi...
- Affected:
- up to 1.6.9.17
- Fixed in:
- 1.6.9.17
- Disclosed:
- Dec 19, 2025
CVE-2025-13754 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, which le...
- CVSS:
- 5.3
- Affected:
- up to 1.6.9.16
- Fixed in:
- 1.6.9.17
- Disclosed:
- Dec 18, 2025
CVE-2025-13754 on NVD →
Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to i...
- CVSS:
- 6.4
- Affected:
- up to 1.6.8.30
- Fixed in:
- 1.6.8.32
- Disclosed:
- Jun 13, 2025
CVE-2025-4667 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor...
- CVSS:
- 7.3
- Affected:
- up to 1.6.8.5
- Fixed in:
- 1.6.8.7
- Disclosed:
- Mar 12, 2025
CVE-2025-1119 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.8.5
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it p...
- Affected:
- up to 1.6.8.5
- Fixed in:
- 1.6.8.5
- Disclosed:
- Mar 7, 2025
CVE-2024-13431 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 6.1
- Affected:
- up to 1.6.8.3
- Fixed in:
- 1.6.8.5
- Disclosed:
- Mar 6, 2025
CVE-2024-13431 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.7.55
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 1.6.7.55
- Fixed in:
- 1.6.7.55
- Disclosed:
- Nov 5, 2024
CVE-2024-7877 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.7.55
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 1.6.7.55
- Fixed in:
- 1.6.7.55
- Disclosed:
- Nov 5, 2024
CVE-2024-7876 on NVD →
Appointment Booking Calendar <= - Authenticated (Admin+) Stored Cross-Site Scripting via Notification Settings
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via notification settings in all versions up to, and including, 1.6.7.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 4.4
- Affected:
- up to 1.6.7.53
- Fixed in:
- 1.6.7.55
- Disclosed:
- Oct 15, 2024
CVE-2024-7877 on NVD →
Appointment Booking Calendar <= 1.6.7.53 - Authenticated (Admin+) Stored Cross-Site Scripting via Appointment Settings
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin appointment settings in all versions up to, and including, 1.6.7.53 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
- CVSS:
- 4.4
- Affected:
- up to 1.6.7.53
- Fixed in:
- 1.6.7.55
- Disclosed:
- Oct 15, 2024
CVE-2024-7876 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.7.43
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins
- Affected:
- up to 1.6.7.43
- Fixed in:
- 1.6.7.43
- Disclosed:
- Sep 13, 2024
CVE-2024-7129 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.42 - Authenticated (Admin+) Remote Code Execution
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.6.7.42 via Twig Template Injection. This makes it possible for authenticated attackers, with administrator-level access and above, to execute...
- CVSS:
- 7.2
- Affected:
- up to 1.6.7.42
- Fixed in:
- 1.6.7.43
- Disclosed:
- Aug 23, 2024
CVE-2024-7129 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.7.18
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- Affected:
- up to 1.6.7.18
- Fixed in:
- 1.6.7.18
- Disclosed:
- May 16, 2024
CVE-2024-4288 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 1.6.7.14
- Fixed in:
- 1.6.7.18
- Disclosed:
- May 15, 2024
CVE-2024-4288 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.7.9
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
- Affected:
- up to 1.6.7.9
- Fixed in:
- 1.6.7.9
- Disclosed:
- Apr 9, 2024
CVE-2024-2341 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.7.9
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...
- Affected:
- up to 1.6.7.9
- Fixed in:
- 1.6.7.9
- Disclosed:
- Apr 9, 2024
CVE-2024-2342 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.6.24
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N Squared Simply Schedule Appointments allows Reflected XSS.This issue affects Simply Schedule Appointments: from n/a through 1.6.6.20.
- Affected:
- up to 1.6.6.24
- Fixed in:
- 1.6.6.24
- Disclosed:
- Mar 27, 2024
CVE-2024-22311 on NVD →
Simply Schedule Appointments <= 1.6.6.20 - Reflected Cross-Site Scripting
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 1.6.6.20
- Fixed in:
- 1.6.6.24
- Disclosed:
- Mar 26, 2024
CVE-2024-22311 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...
- CVSS:
- 8.8
- Affected:
- up to 1.6.7.7
- Fixed in:
- 1.6.7.9
- Disclosed:
- Mar 20, 2024
CVE-2024-2342 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection
high
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...
- CVSS:
- 8.8
- Affected:
- up to 1.6.7.7
- Fixed in:
- 1.6.7.9
- Disclosed:
- Mar 20, 2024
CVE-2024-2341 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.6.24
unknown
[en] The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauth...
- Affected:
- up to 1.6.6.24
- Fixed in:
- 1.6.6.24
- Disclosed:
- Mar 6, 2024
CVE-2024-1760 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.6.20 - Cross-Site Request Forgery to Plugin Data Reset
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthentic...
- CVSS:
- 4.3
- Affected:
- up to 1.6.6.20
- Fixed in:
- 1.6.6.24
- Disclosed:
- Mar 5, 2024
CVE-2024-1760 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.6.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N Squared Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin.This issue affects Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: from n/a before 1.6.6.1.
- Affected:
- up to 1.6.6.1
- Fixed in:
- 1.6.6.1
- Disclosed:
- Dec 28, 2023
CVE-2023-50851 on NVD →
Simply Schedule Appointments <= 1.6.5.27 - Authenticated(Administrator+) SQL Injection
medium
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.6.6.1 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
- CVSS:
- 6.6
- Affected:
- up to 1.6.6.1
- Fixed in:
- 1.6.6.1
- Disclosed:
- Dec 21, 2023
CVE-2023-50851 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.5.7.7
unknown
[en] The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.5.7.7
- Fixed in:
- 1.5.7.7
- Disclosed:
- Aug 29, 2022
CVE-2022-2374 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.5.7.7
unknown
[en] The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
- Affected:
- up to 1.5.7.7
- Fixed in:
- 1.5.7.7
- Disclosed:
- Aug 29, 2022
CVE-2022-2373 on NVD →
Simply Schedule Appointments <= 1.5.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.5.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and abo...
- CVSS:
- 5.5
- Affected:
- up to 1.5.7.5
- Fixed in:
- 1.5.7.7
- Disclosed:
- Aug 8, 2022
CVE-2022-2374 on NVD →
Simply Schedule Appointments <= 1.5.7.5 - Unauthenticated Sensitive Information Exposure
medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including 1.5.7.5 due to missing capability checks on the /wp-json/ssa/v1/users REST API endpoint. This makes it possible for unauthenticated attackers to retrieve a list of email addresses assoc...
- CVSS:
- 5.3
- Affected:
- up to 1.5.7.5
- Fixed in:
- 1.5.7.7
- Disclosed:
- Aug 8, 2022
CVE-2022-2373 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.8.32
unknown
- Affected:
- up to 1.6.8.32
- Fixed in:
- 1.6.8.32
CVE-2025-4667 on NVD →
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.8.7
unknown
- Affected:
- up to 1.6.8.7
- Fixed in:
- 1.6.8.7
CVE-2025-1119 on NVD →