Vulnerabilities

Summary — last 7 days

New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
–

39 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedHigh (7.5)——Simply Schedule AppointmentsAI10/1/202610/1/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom…
ReceivedMedium (6.5)——Simply Schedule AppointmentsAI10/1/202610/1/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access…
DeferredMedium (5.3)——Simply Schedule AppointmentsAI9/30/20269/30/2026
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
DeferredMedium (6.5)——Simply Schedule AppointmentsAI9/30/20269/30/2026
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
DeferredHigh (7.5)0.65%—Simply Schedule AppointmentsAI9/30/20269/30/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files…
DeferredHigh (8.8)0.20%—Simply Schedule AppointmentsAI9/2/20269/4/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
DeferredMedium (6.5)0.68%—Simply Schedule Appointments Appointment Booking CalendarAI8/16/20268/20/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for…
DeferredMedium (6.5)0.37%—Simply Schedule AppointmentsAI8/15/20268/26/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
DeferredHigh (7.1)0.25%—Simply Schedule AppointmentsAI8/6/20268/12/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
DeferredCritical (9.3)0.40%—Simply Schedule AppointmentsAI8/6/20268/12/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
DeferredMedium (6.5)0.34%—Simply Schedule AppointmentsAI8/3/20268/26/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,…
DeferredHigh (7.5)0.41%—Simply Schedule AppointmentsAI8/2/20268/26/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
DeferredMedium (6.1)0.25%—Simply Schedule AppointmentsAI7/27/20267/27/2026
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments…
DeferredMedium (6.5)0.27%—Nsquared Simply Schedule AppointmentsAI7/13/20267/13/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
DeferredMedium (6.5)0.33%—Nsquared Simply Schedule AppointmentsAI7/13/20267/13/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.
DeferredHigh (7.1)0.23%—Simply Schedule AppointmentsAI6/26/20266/26/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
DeferredHigh (7.5)0.42%—Simply Schedule AppointmentsAI6/15/20266/17/2026
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
DeferredCritical (9.3)0.40%—Simply Schedule AppointmentsAI6/15/20266/17/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
DeferredHigh (7.1)0.25%—Simply Schedule AppointmentsAI6/15/20266/17/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
DeferredMedium (5.3)0.64%—Booking Calendar Simply Schedule AppointmentsAI5/28/20266/17/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.…
DeferredMedium (5.3)0.44%—Simply Schedule AppointmentsAI5/27/20267/23/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied…
DeferredMedium (5.3)0.26%—Nsquared Simply Schedule AppointmentsAI4/8/20267/24/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.
DeferredHigh (8.5)0.36%—Nsquared Simply Schedule AppointmentsAI4/8/20267/24/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
DeferredMedium (4.3)0.21%—Simply Schedule AppointmentsAI3/13/20266/17/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments`…
DeferredMedium (6.5)0.22%—Nsquared Simply Schedule AppointmentsAI1/22/20266/17/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.