VYPR

Simply Schedule Appointments

by WordPress

Source repositories

CVEs (29)

  • CVE-2026-7493MedMay 27, 2026
    risk 0.27cvss 5.3epss 0.00

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls…

  • CVE-2025-13754MedDec 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at…

  • CVE-2026-16541Aug 15, 2026
    risk 0.00cvss epss

    The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of…

  • CVE-2026-15254MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to…

  • CVE-2026-16540HigAug 2, 2026
    risk 0.00cvss 7.5epss 0.00

    The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions,…

  • CVE-2026-13400MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed…

  • CVE-2026-59523MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.

  • CVE-2026-57812MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.

  • CVE-2026-57317HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

Page 2 of 2