CVE-2026-84764: WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simply Schedule Appointmentsto a version that resolves this vulnerability.Fixed in 1.6.12.24
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must cause a user to interact with a crafted request, as indicated by the user-interaction requirement in the CVSS vector. The vulnerability can be reached over the network and does not require the attacker to authenticate first.
Which installations are affected?
WordPress sites using Simply Schedule Appointments version 1.6.12.23 or earlier are affected according to the available data.
How serious could successful exploitation be?
The supplied CVSS vector rates the issue as high severity with a score of 8.8. It indicates potential high impact to confidentiality, integrity, and availability.