CVE Database /
CVE-2026-65513
CVE · High
CVE-2026-65513 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-65513
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 1.6.12.11
|
1.6.12.11 |
2026-07-28 |
—
|
CVE-2026-65513
The Simply Schedule Appointments plugin for WordPress contains a security flaw that allows malicious code to be embedded in the application, which can then be executed by users who access affected pages, even if they are not logged in. This vulnerability arises from inadequate measures to prevent tainted input from being rendered as part of the page output. Versions prior to 1.6.12.10 are susceptible to this issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings