Plugin Vulnerability Hub
Plugin 22 known issues Latest disclosed Mar 18, 2026

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Vulnerabilities

Review known vulnerability records for the WordPress plugin Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin (`simply-schedule-appointments`), including severity, CVE references, affected versions, and patch status.

Known Records
22
High or Critical
8
Linked CVEs
22
Last Updated
Mar 18, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
22 records include a published patch path.
Severity Mix
0 critical and 8 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-3658
Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of suf...

Published
Mar 18, 2026
Patched Release
1.6.10.2
Affected Versions
Versions up to 1.6.10.0
Next Step
Update to 1.6.10.2 or newer if supported.
Plugin High Patched: Yes CVE-2026-3045
Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint

The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to u...

Published
Mar 12, 2026
Patched Release
1.6.10.0
Affected Versions
Versions up to 1.6.9.29
Next Step
Update to 1.6.10.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1704
Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users wi...

Published
Mar 12, 2026
Patched Release
1.6.10.0
Affected Versions
Versions up to 1.6.9.29
Next Step
Update to 1.6.10.0 or newer if supported.
Plugin High Patched: Yes CVE-2026-1708
Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent t...

Published
Mar 10, 2026
Patched Release
1.6.9.29
Affected Versions
Versions up to 1.6.9.27
Next Step
Update to 1.6.9.29 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-69315
Simply Schedule Appointments <= 1.6.9.15 - Missing Authorization

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.9.15. This makes it possible for unauthenticated atta...

Published
Jan 20, 2026
Patched Release
1.6.9.17
Affected Versions
Versions up to 1.6.9.15
Next Step
Update to 1.6.9.17 or newer if supported.
Plugin High Patched: Yes CVE-2025-12166
Simply Schedule Appointments <= 1.6.9.9 - Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user suppli...

Published
Jan 14, 2026
Patched Release
1.6.9.13
Affected Versions
Versions up to 1.6.9.9
Next Step
Update to 1.6.9.13 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11723
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possib...

Published
Jan 05, 2026
Patched Release
1.6.9.6
Affected Versions
Versions up to 1.6.9.5
Next Step
Update to 1.6.9.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13754
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner...

Published
Dec 18, 2025
Patched Release
1.6.9.17
Affected Versions
Versions up to 1.6.9.16
Next Step
Update to 1.6.9.17 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4667
Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions...

Published
Jun 13, 2025
Patched Release
1.6.8.32
Affected Versions
Versions up to 1.6.8.30
Next Step
Update to 1.6.8.32 or newer if supported.
Plugin High Patched: Yes CVE-2025-1119
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly...

Published
Mar 12, 2025
Patched Release
1.6.8.7
Affected Versions
Versions up to 1.6.8.5
Next Step
Update to 1.6.8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13431
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization a...

Published
Mar 06, 2025
Patched Release
1.6.8.5
Affected Versions
Versions up to 1.6.8.3
Next Step
Update to 1.6.8.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-7876
Appointment Booking Calendar <= 1.6.7.53 - Authenticated (Admin+) Stored Cross-Site Scripting via Appointment Settings

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin appointment settings in all versions up to, and including, 1.6.7.53 due to insufficient input sanitization and output escapin...

Published
Oct 15, 2024
Patched Release
1.6.7.55
Affected Versions
Versions up to 1.6.7.53
Next Step
Update to 1.6.7.55 or newer if supported.