CVE-2026-39495: WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39495?
CVE-2026-39495 is a high severity SQL Injection vulnerability that can lead to unauthorized data access.
What specific versions of the Simply Schedule Appointments plugin are affected by CVE-2026-39495?
CVE-2026-39495 affects the Simply Schedule Appointments plugin versions up to and including 1.6.9.27.
How do I fix CVE-2026-39495?
To fix CVE-2026-39495, users should update the Simply Schedule Appointments plugin to a version that is higher than 1.6.9.27.
What are the potential impacts of CVE-2026-39495 on my website?
The potential impacts include exposure of sensitive data, unauthorized database manipulation, and compromised website integrity.
Is CVE-2026-39495 being actively exploited in the wild?
Currently, there is no public information confirming that CVE-2026-39495 is being actively exploited, but it is advised to apply patches promptly.