CVE · Medium

CVE-2024-7876 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7876 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.7.55 1.6.7.55 2024-10-15

CVE-2024-7876

A WordPress plugin called Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin contains a security flaw that allows malicious code injection through admin appointment settings, specifically affecting versions 1.6.7.53 and earlier. The issue arises from inadequate filtering of user input and insufficient protection against script execution on the affected pages. This vulnerability is confined to multi-site installations where certain HTML restrictions are in place.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.