CVE · Medium

CVE-2024-2341 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2341 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 1.6.7.9 1.6.7.9 2024-03-20

CVE-2024-2341

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress contains a SQL injection vulnerability affecting versions through 1.6.7.7 in the keys parameter. The vulnerability exists because user-supplied input is not properly escaped and database queries lack adequate parameterization. Authenticated users with subscriber-level permissions or higher can exploit this flaw to inject malicious SQL code and access sensitive data stored in the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.