CVE · Medium

CVE-2024-13431 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13431 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.8.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.6.8.5 1.6.8.5 2025-03-06

CVE-2024-13431

The Simply Schedule Appointments plugin through version 1.6.8.3 contains a reflected cross-site scripting vulnerability in the accent_color and background parameters that fails to properly sanitize input or escape output. An unauthenticated attacker can exploit this flaw by crafting a malicious link that, when clicked by a user, executes arbitrary JavaScript code within the victim's browser.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.