SecAlerts
S

Simply Schedule Appointments

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 6, 2024 to present

18
Total CVEs
9
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
42/100
medium
🆕 5Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
0
High
9
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
5
2
XSS
4
3
Code Injection
1
4
CSRF
1

Most Affected Products

1. Simply Schedule Appointments Simply Schedule Appointments6
2. Simply Schedule Appointments Booking Plugin5
3. Nsquared Simply Schedule Appointments Wordpress4
4. Simply Schedule Appointments Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin2
5. Simply Schedule Appointments Simply Schedule Appointments Booking Plugin2

Recent Vulnerabilities

See more →
CVE-2026-91109
CVSS 6.5medium

Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter

Oct 1, 2026🔧 No Patch
CVE-2026-92245
CVSS 7.5high

Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce

Oct 1, 2026🔧 No Patch
CVE-2026-94673
CVSS 5.3medium

WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability

Sep 30, 2026🔧 No Patch
CVE-2026-94074
CVSS 6.5medium

WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability

Sep 30, 2026🔧 No Patch
CVE-2026-89294
CVSS 7.5high

Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter

Sep 30, 2026🔧 No Patch
CVE-2026-39447
CVSS 7.1high

WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-6937
CVSS 5.3medium

Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint

May 28, 2026🔧 No Patch
CVE-2026-7797
CVSS 7.5high

Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter

May 28, 2026🔧 No Patch
CVE-2026-7493
CVSS 5.3medium

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service

May 27, 2026🔧 No Patch
CVE-2026-3658
CVSS 7.5EPSS 0%high

Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter

Mar 19, 2026🔧 No Patch

Monitor Simply Schedule Appointments in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Simply Schedule Appointments Security Vulnerabilities & Risk Score | 18 CVEs | SecAlerts - SecAlerts