CVE · High

CVE-2026-39495 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39495 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29 High 8.5 < 1.6.9.29 1.6.9.29 2026-03-26

CVE-2026-39495

The Simply Schedule Appointments plugin for WordPress contains a security flaw in versions up to 1.6.9.27, allowing malicious users with contributor-level access or higher to inject unauthorized SQL code into database queries. This vulnerability arises from inadequate protection of user-submitted input and insufficient modification of existing SQL statements. As a result, attackers can potentially extract confidential data from the site's database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.