Junglewise Threat Intelligence

CVE-2026-57317: NSquared Simply Schedule Appointments unauthenticated XSS

CVE-2026-57317 · Severity: high · CVSS 7.1 · Published 2026-06-26

Technologies: NSquared Simply Schedule Appointments.

Executive brief

Simply Schedule Appointments, a popular WordPress plugin used for managing bookings and client meetings, contains a security flaw that allows attackers to inject malicious scripts into the website. Because this vulnerability can be exploited without logging in, an attacker could trick a site administrator or visitor into clicking a link that executes code in their browser. This could lead to unauthorized actions being performed on behalf of the user, such as redirecting visitors to malicious sites or stealing sensitive session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the NSquared Simply Schedule Appointments plugin for WordPress (versions <= 1.6.12.2). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking a victim (typically an administrator or authenticated user) into visiting it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.6.12.4.

Affected products

  • NSquared Simply Schedule Appointments <= 1.6.12.2

Timeline

  • 2026-06-06: disclosed: Reported by vnth4nhnt
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Patch available in version 1.6.12.4

References