CVE Database /
CVE-2026-7493
CVE · Medium
CVE-2026-7493 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-7493
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.7 |
Uncontrolled Resource Consumption |
Medium
5.3
|
< 1.6.11.7
|
1.6.11.7 |
2026-05-26 |
—
|
CVE-2026-7493
The Simply Schedule Appointments Booking Plugin for WordPress contains a flaw in its REST API endpoint, allowing an attacker to trigger a denial of service condition by submitting a user-defined delay value without any restrictions on frequency. This vulnerability affects all plugin versions up to and including 1.6.11.5, enabling unauthenticated attackers to consume system resources and block legitimate users from accessing the site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings