CVE-2026-94074: WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
Affected Software
1 affected component
Simply Schedule Appointments Simply Schedule Appointments<=1.6.12.29
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simply Schedule Appointments pluginto a version that resolves this vulnerability.Fixed in 1.6.12.31
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
2
Which installations are affected?
Simply Schedule Appointments versions 1.6.12.29 and earlier are affected according to the available information.
3
What impact is indicated by the severity data?
The supplied CVSS vector indicates low confidentiality and integrity impact, with no availability impact. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.