CVE-2026-65508: WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simply Schedule Appointments Pluginto a version that resolves this vulnerability.Fixed in 1.6.12.11