Junglewise Threat Intelligence

CVE-2026-39493: NSquared Simply Schedule Appointments SQL injection

CVE-2026-39493 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Technologies: NSquared Simply Schedule Appointments.

Executive brief

Simply Schedule Appointments is a WordPress plugin used by businesses to manage client bookings and appointments. A security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, appointment records, or other private data stored on the site.

Technical details

The Simply Schedule Appointments plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability exists in versions up to and including 1.6.9.27. A remote, unauthenticated attacker can exploit this flaw via a network request to execute arbitrary SQL queries. This allows for the unauthorized retrieval of sensitive data from the database. The issue has been addressed in version 1.6.9.29.

Affected products

  • NSquared Simply Schedule Appointments <= 1.6.9.27

Timeline

  • 2026-01-25: other: Reported by researcher Doan Dinh Van
  • 2026-04-08: advisory: Patchstack published advisory
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-04-08: patched: Version 1.6.9.29 released

References