Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Simply Schedule Appointments — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Simply Schedule Appointments, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability information for the vendor product "Simply Schedule Appointments." It collects documented security weaknesses associated with this specific scheduling application, covering advisories released from the product's initial release through the present day. You can use this page to track the vendor's security advisories, understand the recurring weakness classes affecting the software, and review the product's complete vulnerability history. By consolidating these records in one location, the page supports efficient monitoring of new findings and pattern analysis over time.

Vendor: N Squared

CVE ID Title CVSS Severity Published
CVE-2026-91109 Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter CWE-639 6.5 Medium 2026-10-01
CVE-2026-92245 Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce CWE-862 7.5 High 2026-10-01
CVE-2026-94673 WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability CWE-639 5.3 Medium 2026-09-30
CVE-2026-94074 WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-09-30
CVE-2026-89294 Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter CWE-98 7.5 High 2026-09-30
CVE-2026-84764 WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 8.8 High 2026-09-02
CVE-2026-13358 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure CWE-639 6.5 Medium 2026-08-16
CVE-2026-16541 Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints - - 2026-08-15
CVE-2026-65513 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-08-06
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-08-06
CVE-2026-15254 Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode - - 2026-08-03
CVE-2026-16540 Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint - - 2026-08-02
CVE-2026-13400 Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information - - 2026-07-27
CVE-2026-57812 WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-07-13
CVE-2026-59523 WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-07-13
CVE-2026-57317 WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-06-26
CVE-2026-42384 WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability CWE-201 7.5 High 2026-06-15
CVE-2026-39493 WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-06-15
CVE-2026-39447 WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-06-15
CVE-2026-39694 WordPress Simply Schedule Appointments plugin <= 1.6.10.2 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-04-08
CVE-2026-39495 WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability CWE-89 8.5 High 2026-04-08
CVE-2025-69315 WordPress Simply Schedule Appointments plugin <= 1.6.9.15 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-01-22
CVE-2024-22311 WordPress Simply Schedule Appointments plugin <= 1.6.6.20 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-27

All 23 known CVE vulnerabilities affecting Simply Schedule Appointments with full Chinese analysis, references, and POCs where available.