CVE · High

CVE-2026-65513 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-65513 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.6.12.11 1.6.12.11 2026-07-28

CVE-2026-65513

The Simply Schedule Appointments plugin for WordPress contains a security flaw that allows malicious code to be embedded in the application, which can then be executed by users who access affected pages, even if they are not logged in. This vulnerability arises from inadequate measures to prevent tainted input from being rendered as part of the page output. Versions prior to 1.6.12.10 are susceptible to this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.