CVE · High

CVE-2023-50851 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-50851 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.6.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 1.6.6.1 1.6.6.1 2023-12-21

CVE-2023-50851

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress allows authenticated administrators and higher-privileged users to execute arbitrary SQL queries through an unspecified parameter that is not properly escaped or parameterized. This vulnerability affects all versions before 1.6.6.1 and enables attackers with administrative access to manipulate database queries and retrieve sensitive information. The flaw stems from inadequate input sanitization and the failure to use prepared statements when constructing SQL queries.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.