Executive brief
Simply Schedule Appointments is a popular WordPress plugin used by businesses to manage customer bookings and schedules. A security vulnerability in this plugin allows an attacker with basic user permissions to interact directly with the website's database. This could lead to the theft of sensitive customer information or unauthorized access to internal site data.
Technical details
A Blind SQL Injection vulnerability exists in the NSquared Simply Schedule Appointments plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw is present in versions up to and including 1.6.9.27. An attacker with 'Contributor' level privileges or higher can exploit this vulnerability via network requests to execute arbitrary SQL queries. This allows for the unauthorized extraction of sensitive data from the database. The issue has been addressed in version 1.6.9.29.
Affected products
- NSquared Simply Schedule Appointments <= 1.6.9.27
Timeline
- 2026-02-24: other: Vulnerability reported by researcher daroo
- 2026-03-26: advisory: Patchstack published advisory and assigned PSID 4f8f48f2da21
- 2026-04-08: disclosed: CVE-2026-39495 published
- 2026-06-17: patched: Patch confirmed available in version 1.6.9.29