CVE · Medium

CVE-2024-7877 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7877 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.7.55 1.6.7.55 2024-10-15

CVE-2024-7877

A vulnerability exists in the Appointment Booking Calendar plugin for WordPress, affecting versions up to 1.6.7.53. The issue arises from inadequate validation of input data and failure to properly prevent malicious code injection when configuring notification settings. As a result, authorized attackers with elevated permissions can embed malicious scripts that will be executed whenever users access specific pages on affected multi-site installations or those where unfiltered HTML is restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.