CVE-2023-50851
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress allows authenticated administrators and higher-privileged users to execute arbitrary SQL queries through an unspecified parameter that is not properly escaped or parameterized. This vulnerability affects all versions before 1.6.6.1 and enables attackers with administrative access to manipulate database queries and retrieve sensitive information. The flaw stems from inadequate input sanitization and the failure to use prepared statements when constructing SQL queries.
Based on public CVE data (MITRE/NVD).