Executive brief
Simply Schedule Appointments is a WordPress plugin used by businesses to manage client bookings and appointments. A security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, appointment records, or other private data stored on the site.
Technical details
The Simply Schedule Appointments plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability exists in versions up to and including 1.6.9.27. A remote, unauthenticated attacker can exploit this flaw via a network request to execute arbitrary SQL queries. This allows for the unauthorized retrieval of sensitive data from the database. The issue has been addressed in version 1.6.9.29.
Affected products
- NSquared Simply Schedule Appointments <= 1.6.9.27
Timeline
- 2026-01-25: other: Reported by researcher Doan Dinh Van
- 2026-04-08: advisory: Patchstack published advisory
- 2026-06-15: disclosed: CVE published to NVD
- 2026-04-08: patched: Version 1.6.9.29 released