Cross-Site Scripting
10 records28.6%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 35 vulnerability records associated with Simply Schedule Appointments, published between 2022 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2022 | 2 | |
| 2023 | 1 | |
| 2024 | 8 | |
| 2025 | 4 | |
| 2026 | 20 |
| Severity | Records | Share |
|---|---|---|
| High | 13 | 37.1% |
| Medium | 22 | 62.9% |
First: 2022. Latest: 2026.
First: 2023. Latest: 2026.
First: 2025. Latest: 2026.
First: 2022. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.6.12.01.6.12.61.6.12.41.6.11.01.6.11.91.6.11.71.6.111.6.11.21.6.10.21.6.10.01.6.9.291.6.11.11.6.9.171.6.9.131.6.9.61.6.8.321.6.8.71.6.8.51.6.7.551.6.7.431.6.7.181.6.7.91.6.6.241.6.6.11.5.7.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.6.11.11 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization | July 9, 2026 | 1.6.12.0 | Medium |
*-1.6.12.4 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization | July 9, 2026 | 1.6.12.6 | Medium |
*-1.6.12.3 | Simply Schedule Appointments <= 1.6.12.3 - Unauthenticated Stored Cross-Site Scripting | July 6, 2026 | 1.6.12.4 | High |
*-1.6.12.2 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.2 - Unauthenticated Stored Cross-Site Scripting | June 26, 2026 | 1.6.12.4 | High |
*-1.6.10.6 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.10.6 - Unauthenticated Stored Cross-Site Scripting | May 28, 2026 | 1.6.11.0 | High |
*-1.6.11.8 | Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint | May 27, 2026 | 1.6.11.9 | Medium |
*-1.6.11.8 | Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter | May 27, 2026 | 1.6.11.9 | High |
*-1.6.11.5 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service | May 26, 2026 | 1.6.11.7 | Medium |
*-1.6.10.6 | Appointment Booking Calendar <= 1.6.10.6 - Unauthenticated Arbitrary Appointment View, Modification and Deletion | May 6, 2026 | 1.6.11 | Medium |
[*, 1.6.11.2) | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin < 1.6.11.2 - Unauthenticated Sensitive Information Exposure | April 27, 2026 | 1.6.11.2 | Medium |
*-1.6.9.27 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.27 - Unauthenticated SQL Injection | April 8, 2026 | 1.6.9.29 | High |
*-1.6.9.27 | Simply Schedule Appointments <= 1.6.9.27 - Authenticated (Contributor+) SQL Injection | March 26, 2026 | 1.6.9.29 | Medium |
*-1.6.10.0 | Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter | March 18, 2026 | 1.6.10.2 | High |
*-1.6.9.29 | Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint | March 12, 2026 | 1.6.10.0 | High |
*-1.6.9.29 | Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure | March 12, 2026 | 1.6.10.0 | Medium |
*-1.6.9.27 | Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter | March 10, 2026 | 1.6.9.29 | High |
*-1.6.11.0 | Simply Schedule Appointments <= 1.6.11.0 - Missing Authorization | February 26, 2026 | 1.6.11.1 | Medium |
*-1.6.9.15 | Simply Schedule Appointments <= 1.6.9.15 - Missing Authorization | January 20, 2026 | 1.6.9.17 | Medium |
*-1.6.9.9 | Simply Schedule Appointments <= 1.6.9.9 - Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters | January 14, 2026 | 1.6.9.13 | High |
*-1.6.9.5 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure | January 5, 2026 | 1.6.9.6 | Medium |
*-1.6.9.16 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure | December 18, 2025 | 1.6.9.17 | Medium |
*-1.6.8.30 | Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes | June 13, 2025 | 1.6.8.32 | Medium |
*-1.6.8.5 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution | March 12, 2025 | 1.6.8.7 | High |
*-1.6.8.3 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting | March 6, 2025 | 1.6.8.5 | Medium |
*-1.6.7.53 | Appointment Booking Calendar <= 1.6.7.53 - Authenticated (Admin+) Stored Cross-Site Scripting via Appointment Settings | October 15, 2024 | 1.6.7.55 | Medium |
Selected source records
Published: July 9, 2026
Published: July 9, 2026
Published: July 6, 2026
Published: June 26, 2026
Published: May 28, 2026
Published: May 27, 2026
Published: May 27, 2026
Published: May 26, 2026
Published: March 20, 2024
Published: March 20, 2024
Published: January 14, 2026
Published: March 12, 2026
Published: March 18, 2026
Published: March 10, 2026
Published: April 8, 2026
Published: May 27, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.