Junglewise Threat Intelligence

CVE-2026-39447: NSquared Simply Schedule Appointments unauthenticated XSS

CVE-2026-39447 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: NSquared Simply Schedule Appointments.

Executive brief

Simply Schedule Appointments is a WordPress plugin used by businesses to manage client bookings and scheduling. A security flaw in this plugin allows an unauthenticated attacker to inject malicious scripts into the website. If a site visitor or administrator interacts with a specially crafted link or page, the attacker could steal session information, redirect users to malicious sites, or perform unauthorized actions on behalf of the user.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Simply Schedule Appointments plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability affects versions up to and including 1.6.10.6. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is an authenticated administrator. The issue is resolved in version 1.6.11.0.

Affected products

  • NSquared Simply Schedule Appointments <= 1.6.10.6

Timeline

  • 2026-04-06: other: Reported by researcher devploit
  • 2026-05-28: advisory: Initial advisory published by Patchstack
  • 2026-05-28: patched: Patch released in version 1.6.11.0
  • 2026-06-15: disclosed: CVE published to NVD

References