Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin, with AI-generated Chinese analysis, references, and POCs.

The vulnerability aggregation page for Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin provides a centralized repository of identified security weaknesses within the software ecosystem. This resource specifically targets common weakness types associated with the plugin, ensuring that developers, security researchers, and administrators have access to a consolidated view of potential threats. The page collects detailed information regarding various vulnerabilities discovered in the product, covering incidents from its initial release through recent updates to the present day. By aggregating these data points, the platform aims to offer transparency into the security posture of the appointment booking tool over time. Users can leverage this page to track a vendor's advisories as they are issued, gaining insight into how quickly and effectively known issues are being addressed. Additionally, the page serves as an educational resource that allows visitors to understand a specific weakness class in the context of real-world implementations within appointment scheduling systems. It also enables users to look up a product's vulnerability history, providing a chronological timeline of security events and patches. This comprehensive approach helps stakeholders make informed decisions about updating, configuring, or replacing components based on empirical security data rather than speculation. The content is structured to facilitate easy navigation between different vulnerability categories and severity levels, ensuring that technical details are accessible without overwhelming the reader. By focusing on factual reporting and historical context, this page supports proactive risk management for organizations relying on this specific booking solution.

Vendor: N Squared

CVE ID Title CVSS Severity Published
CVE-2026-6937 Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint CWE-862 5.3 Medium 2026-05-28
CVE-2026-7797 Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter CWE-89 7.5 High 2026-05-28
CVE-2026-7493 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service CWE-400 5.3 Medium 2026-05-27
CVE-2026-4807 Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion CWE-862 6.5 Medium 2026-05-07
CVE-2026-3658 Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter CWE-89 7.5 High 2026-03-19
CVE-2026-1704 Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure CWE-639 4.3 Medium 2026-03-13
CVE-2026-3045 Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint CWE-862 7.5 High 2026-03-13
CVE-2026-1708 Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter CWE-89 7.5 High 2026-03-11
CVE-2025-12166 Simply Schedule Appointments <= 1.6.9.9 - Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters CWE-89 7.5 High 2026-01-14
CVE-2025-11723 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure CWE-330 6.5 Medium 2026-01-06
CVE-2025-13754 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure CWE-862 5.3 Medium 2025-12-19
CVE-2025-4667 Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes CWE-79 6.4 Medium 2025-06-14
CVE-2025-1119 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution CWE-94 7.3 High 2025-03-13
CVE-2024-13431 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting CWE-79 6.1 Medium 2025-03-07
CVE-2024-7877 Appointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS 4.8AI Medium AI 2024-11-05
CVE-2024-7876 Appointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS 4.8AI Medium AI 2024-11-05
CVE-2024-7129 Appointment Booking Calendar < 1.6.7.43 - Admin+ Template Injection to RCE 7.2AI High AI 2024-09-13
CVE-2024-4288 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-05-16
CVE-2024-2341 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection CWE-89 8.8 High 2024-04-09
CVE-2024-2342 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode CWE-89 8.8 High 2024-04-09
CVE-2024-1760 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.6.20 - Cross-Site Request Forgery to Plugin Data Reset CWE-352 4.3 Medium 2024-03-06
CVE-2023-50851 WordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL Injection CWE-89 7.6 High 2023-12-28

All 22 known CVE vulnerabilities affecting Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin with full Chinese analysis, references, and POCs where available.