CVE Database /
CVE-2024-2341
CVE · Medium
CVE-2024-2341 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2341
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.9 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Medium
6.5
|
< 1.6.7.9
|
1.6.7.9 |
2024-03-20 |
—
|
CVE-2024-2341
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress contains a SQL injection vulnerability affecting versions through 1.6.7.7 in the keys parameter. The vulnerability exists because user-supplied input is not properly escaped and database queries lack adequate parameterization. Authenticated users with subscriber-level permissions or higher can exploit this flaw to inject malicious SQL code and access sensitive data stored in the database.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings