Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesSimply Schedule Appointments

Simply Schedule Appointments vulnerabilities

Simply Schedule Appointments has 27 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
27
Active installs
50,000+
Latest version
1.6.12.33
Last updated
23 Sep 2026
Most recent
1 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-91109
Medium 6.5Up to 1.6.12.31Fixed in a later version (latest 1.6.12.33)6 d ago
Broken access control
CVE-2026-92245
High 7.5Up to 1.6.12.32Fixed in a later version (latest 1.6.12.33)6 d ago
File inclusion
CVE-2026-89294
High 7.5Up to 1.6.12.27Fixed in a later version (latest 1.6.12.33)7 d ago
Broken access control
CVE-2026-13358
Medium 6.5Up to 1.6.12.10Fixed in a later version (latest 1.6.12.33)16 Aug 2026
Sensitive data exposure
CVE-2026-16541
Medium 6.5Before 1.6.12.17Fixed in 1.6.12.1715 Aug 2026
Broken access control
CVE-2026-15254
Medium 6.5Before 1.6.12.11Fixed in 1.6.12.113 Aug 2026
Broken access control
CVE-2026-16540
High 7.5Before 1.6.12.6Fixed in 1.6.12.62 Aug 2026
Broken access control
CVE-2026-6937
Medium 5.3Up to 1.6.11.8Fixed in a later version (latest 1.6.12.33)28 May 2026
SQL injection
CVE-2026-7797
High 7.5Up to 1.6.11.8Fixed in a later version (latest 1.6.12.33)28 May 2026
Denial of service
CVE-2026-7493
Medium 5.3Up to 1.6.11.5Fixed in a later version (latest 1.6.12.33)27 May 2026
Broken access control
CVE-2026-4807
Medium 6.5Up to 1.6.10.6Fixed in a later version (latest 1.6.12.33)7 May 2026
SQL injection
CVE-2026-3658
High 7.5Up to 1.6.10.0Fixed in a later version (latest 1.6.12.33)19 Mar 2026
Broken access control
CVE-2026-3045
High 7.5Up to 1.6.9.29Fixed in a later version (latest 1.6.12.33)13 Mar 2026
Broken access control
CVE-2026-1704
Medium 4.3Up to 1.6.9.29Fixed in a later version (latest 1.6.12.33)13 Mar 2026
SQL injection
CVE-2026-1708
High 7.5Up to 1.6.9.27Fixed in a later version (latest 1.6.12.33)11 Mar 2026
Sensitive data exposure
CVE-2025-13754
Medium 5.3Up to 1.6.9.16Fixed in a later version (latest 1.6.12.33)19 Dec 2025
Cross-site scripting (XSS)
CVE-2025-4667
Medium 6.4Up to 1.6.8.30Fixed in a later version (latest 1.6.12.33)14 Jun 2025
Remote code execution
CVE-2025-1119
High 7.3Up to 1.6.8.5Fixed in a later version (latest 1.6.12.33)13 Mar 2025
Cross-site scripting (XSS)
CVE-2024-13431
Medium 6.1Before 1.6.8.5Fixed in 1.6.8.57 Mar 2025
Cross-site scripting (XSS)
CVE-2024-7876
Medium 4.8Before 1.6.7.55Fixed in 1.6.7.555 Nov 2024
Cross-site scripting (XSS)
CVE-2024-7877
Medium 4.8Before 1.6.7.55Fixed in 1.6.7.555 Nov 2024
Cross-site scripting (XSS)
CVE-2024-4288
Medium 6.4Before 1.6.7.18Fixed in 1.6.7.1816 May 2024
SQL injection
CVE-2024-2341
High 8.8Before 1.6.7.9Fixed in 1.6.7.99 Apr 2024
SQL injection
CVE-2024-2342
High 8.8Before 1.6.7.9Fixed in 1.6.7.99 Apr 2024
Cross-site request forgery (CSRF)
CVE-2024-1760
Medium 4.3Before 1.6.6.24Fixed in 1.6.6.246 Mar 2024
Broken access control
CVE-2022-2373
Medium 5.3Before 1.5.7.7Fixed in 1.5.7.729 Aug 2022
Cross-site scripting (XSS)
CVE-2022-2374
Medium 4.8Before 1.5.7.7Fixed in 1.5.7.729 Aug 2022
Read the published descriptions
CVE-2026-91109, 1 Oct 2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose every co-booker's private per-appointment id_token (exposed as public_token) alongside their PII (name and email address), then use each leaked token to read, overwrite arbitrary appointment meta on, or cancel the co-booker's appointment via the same REST controller. Exploitation requires the attacker to possess a valid id_token for any single appointment within the targeted group booking. CVE record
CVE-2026-92245, 1 Oct 2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII - including names, email addresses, phone numbers, and custom form field data - stored in appointment records, as well as per-appointment public_token values. The leaked per-appointment public_token values also enable unauthenticated attackers to delete arbitrary appointments via the DELETE /wp-json/ssa/v1/appointments/{id} endpoint, which accepts the token as sole authorization. CVE record
CVE-2026-89294, 30 Sep 2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value. CVE record
CVE-2026-13358, 16 Aug 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to access appointment records belonging to arbitrary users and harvest the per-appointment ownership tokens (32-character hashes) embedded in the rendered HTML, which can then be used without any authentication to read or modify those appointments including full customer PII such as name, email, phone number, and private notes. The /wp-json/ssa/v1/render-shortcode REST endpoint is registered unconditionally on rest_api_init regardless of whether the Divi theme is installed, and its permission callback only requires current_user_can('edit_posts'), meaning any Contributor-level account is sufficient to trigger this entire exploit chain. CVE record
CVE-2026-16541, 15 Aug 2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users. CVE record
CVE-2026-15254, 3 Aug 2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site. CVE record
CVE-2026-16540, 2 Aug 2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. CVE record
CVE-2026-6937, 28 May 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint. This makes it possible for unauthenticated attackers to modify arbitrary appointment records including customer PII, payment status, and meeting URL fields, and to expose full customer PII from existing appointment records via the bulk endpoint response. The public nonce is a static, user-independent value present in the HTML source of any page hosting the [ssa_booking] shortcode, meaning any visitor who has viewed such a page can obtain it and target any appointment in the system without authentication. CVE record
CVE-2026-7797, 28 May 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The /appointments/bulk REST endpoint is reachable by unauthenticated attackers because its permission check accepts a public nonce that is embedded in the booking widget's frontend JavaScript (ssa.api.public_nonce) and visible to all site visitors; exploitation requires issuing the request as a PUT with an application/x-www-form-urlencoded body so that PHP's superglobals are not populated and the blocklist check silently passes. CVE record
CVE-2026-7493, 27 May 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied delay parameter without any rate limiting. This makes it possible for unauthenticated attackers to exhaust PHP worker processes, denying access to the site to legitimate users. CVE record
CVE-2026-4807, 7 May 2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce value through the /wp-json/ssa/v1/embed-inner endpoint, which is accessible to unauthenticated users. The appointment deletion endpoint at /wp-json/ssa/v1/appointments/{id}/delete and /wp-json/ssa/v1/appointments/bulk use a permission check that accepts requests containing both an X-WP-Nonce header (with any arbitrary value) and an X-PUBLIC-Nonce header (with the valid public nonce). When the X-WP-Nonce validation fails, the function falls back to validating the X-PUBLIC-Nonce without properly rejecting the request. Since the public_nonce is exposed to all unauthenticated visitors and is site-wide (not user-specific or appointment-specific), attackers can obtain it and use it to view details of arbitrary appointments, including the public_edit_url, or delete arbitrary appointments by ID. This makes it possible for unauthenticated attackers to view, delete or modify any appointment in the system, disclosing sensitive appointment data, causing service disruption, and loss of booking records. CVE record
CVE-2026-3658, 19 Mar 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, including usernames, email addresses, and password hashes. CVE record
CVE-2026-3045, 13 Mar 2026
The Appointment Booking Calendar - Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users through the public `/wp-json/ssa/v1/embed-inner` REST endpoint, and (2) the `get_item()` method in `SSA_Settings_Api` relies on `nonce_permissions_check()` for authorization (which accepts the public nonce) but does not call `remove_unauthorized_settings_for_current_user()` to filter restricted fields. This makes it possible for unauthenticated attackers to access admin-only plugin settings including the administrator email, phone number, internal access tokens, notification configurations, and developer settings via the `/wp-json/ssa/v1/settings/{section}` endpoint. The exposure of appointment tokens also allows an attacker to modify or cancel appointments. CVE record
CVE-2026-1704, 13 Mar 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments` capability without validating staff ownership of the requested appointment. This makes it possible for authenticated attackers, with custom-level access and above (users granted the ssa_manage_appointments capability, such as Team Members), to view appointment records belonging to other staff members and access sensitive customer personally identifiable information via the appointment ID parameter. CVE record
CVE-2026-1708, 11 Mar 2026
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent the `append_where_sql` parameter from being passed through JSON request bodies, while only checking for its presence in the `$_REQUEST` superglobal. This makes it possible for unauthenticated attackers to append arbitrary SQL commands to queries and extract sensitive information from the database via the `append_where_sql` parameter in JSON payloads granted they have obtained a valid `public_token` that is inadvertently exposed during the booking flow. CVE record
CVE-2025-13754, 19 Dec 2025
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, which leaks plugin settings including staff names, business names, and configuration data that are not publicly displayed on the booking form. This makes it possible for unauthenticated attackers to extract private business configuration. In premium versions with integrations configured, this might also expose other sensitive data including API keys for external services. CVE record
CVE-2025-4667, 14 Jun 2025
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-1119, 13 Mar 2025
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. CVE record
CVE-2024-13431, 7 Mar 2025
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2024-7876, 5 Nov 2024
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed CVE record
CVE-2024-7877, 5 Nov 2024
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed CVE record
CVE-2024-4288, 16 May 2024
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2341, 9 Apr 2024
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-2342, 9 Apr 2024
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-1760, 6 Mar 2024
The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2022-2373, 29 Aug 2022
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address CVE record
CVE-2022-2374, 29 Aug 2022
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) CVE record

What to do if you run Simply Schedule Appointments

If you run Simply Schedule Appointments, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Simply Schedule Appointments vulnerabilities

Free. We email you when a new vulnerability is published for Simply Schedule Appointments, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support