CVE Database /
CVE-2026-42384
CVE · High
CVE-2026-42384 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-42384
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.2 |
Insertion of Sensitive Information Into Sent Data |
High
7.5
|
< 1.6.11.2
|
1.6.11.2 |
2026-04-27 |
—
|
CVE-2026-42384
The Simply Schedule Appointments Booking Plugin, used with WordPress, contains a security flaw that allows unauthorized access to confidential information stored within the plugin's database in versions prior to 1.6.11.2. As a result, malicious users can obtain sensitive details about users and the plugin's configuration without needing authentication credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings