Junglewise Threat Intelligence

CVE-2026-84764: NSquared Simply Schedule Appointments CSRF

CVE-2026-84764 · Severity: high · CVSS 8.8 · Published 2026-09-02

Technologies: NSquared Simply Schedule Appointments.

Executive brief

Simply Schedule Appointments is a WordPress plugin that allows users to schedule appointments through their websites. An unauthenticated attacker can craft a malicious page that tricks logged-in site administrators into performing unintended actions, such as creating or modifying appointments, without their knowledge or consent. This could lead to disruption of appointment scheduling services or unauthorized administrative changes.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Simply Schedule Appointments plugin versions up to 1.6.12.23 that fails to properly validate or sanitize request origins before executing sensitive actions. The vulnerability requires no authentication to initiate but does require user interaction—specifically, a logged-in user (such as a site administrator) must be tricked into visiting a malicious webpage or clicking a crafted link. An attacker can exploit this to perform arbitrary actions within the plugin's scope, such as modifying appointments or settings. The vulnerability was patched in version 1.6.12.24.

Affected products

  • NSquared Simply Schedule Appointments <= 1.6.12.23

Timeline

  • 2026-08-10: disclosed: Reported by Anthony Green of Greenhat Security
  • 2026-09-02: advisory: Published by Patchstack and assigned CVE-2026-84764
  • 2026-09-02: patched: Patched in version 1.6.12.24

References