PLUGIN SECURITY

Is Simply Schedule Appointments safe?

Unlimited appointments, booking calendars, and notifications. Powerful appointment booking plugin and booking system. Start scheduling for free today!

What this plugin does

  • Slug: simply-schedule-appointments
  • Author: NSquared
  • 50000+ active installs
  • 100/100 rating (155 reviews on wordpress.org)
  • 4076186 all-time downloads
  • On WordPress.org since 2018-05-23

appointment bookingappointmentsbookingbooking systemscheduling

Maintenance status

  • Latest known version: 1.6.12.15
  • Last updated: 2026-08-18 10:06pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

41 known CVEs on file for Simply Schedule Appointments.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13358 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 Authorization Bypass Through User-Controlled Key Medium 6.5 < 1.6.12.11 1.6.12.11 2026-08-15 ✓ fixed in latest
CVE-2026-16541 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.17 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 1.6.12.17 1.6.12.17 2026-08-15 ⚠ update needed
CVE-2026-15254 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 Incorrect Authorization Unknown < 1.6.12.11 1.6.12.11 2026-08-03 ✓ fixed in latest
CVE-2026-16540 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.6 Incorrect Authorization Unknown < 1.6.12.6 1.6.12.6 2026-08-02 ✓ fixed in latest
CVE-2026-65513 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.6.12.11 1.6.12.11 2026-07-28 ✓ fixed in latest
CVE-2026-65508 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.11 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 1.6.12.11 1.6.12.11 2026-07-28 ✓ fixed in latest
CVE-2026-57812 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.6 Medium 6.5 < 1.6.12.6 1.6.12.6 2026-07-09 ✓ fixed in latest
CVE-2026-59523 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.0 Medium 6.5 < 1.6.12.0 1.6.12.0 2026-07-09 ✓ fixed in latest
+ 40 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57317 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.6.12.4 1.6.12.4 2026-06-26 ✓ fixed in latest
CVE-2026-39447 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.6.11.0 1.6.11.0 2026-05-28 ✓ fixed in latest
CVE-2026-7797 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.6.11.9 1.6.11.9 2026-05-27 ✓ fixed in latest
CVE-2026-6937 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.9 Missing Authorization Medium 5.3 < 1.6.11.9 1.6.11.9 2026-05-27 ✓ fixed in latest
CVE-2026-7493 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.7 Uncontrolled Resource Consumption Medium 5.3 < 1.6.11.7 1.6.11.7 2026-05-26 ✓ fixed in latest
CVE-2026-4807 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11 Missing Authorization Medium 6.5 < 1.6.11 1.6.11 2026-05-06 ✓ fixed in latest
CVE-2026-42384 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.2 Insertion of Sensitive Information Into Sent Data High 7.5 < 1.6.11.2 1.6.11.2 2026-04-27 ✓ fixed in latest
CVE-2026-39493 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 1.6.9.29 1.6.9.29 2026-04-08 ✓ fixed in latest
CVE-2026-39495 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29 High 8.5 < 1.6.9.29 1.6.9.29 2026-03-26 ✓ fixed in latest
CVE-2026-39694 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.1 Medium 5.3 < 1.6.11.1 1.6.11.1 2026-02-26 ✓ fixed in latest
CVE-2025-69315 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17 Missing Authorization Medium 6.5 < 1.6.9.17 1.6.9.17 2026-01-20 ✓ fixed in latest
CVE-2025-12166 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.13 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.6.9.13 1.6.9.13 2026-01-14 ✓ fixed in latest
CVE-2025-11723 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.6 Use of Insufficiently Random Values Medium 6.5 < 1.6.9.6 1.6.9.6 2026-01-05 ✓ fixed in latest
CVE-2025-13754 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17 Missing Authorization Medium 5.3 < 1.6.9.17 1.6.9.17 2025-12-18 ✓ fixed in latest
CVE-2024-13431 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.8.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.6.8.5 1.6.8.5 2025-03-06 ✓ fixed in latest
CVE-2024-7877 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.7.55 1.6.7.55 2024-10-15 ✓ fixed in latest
CVE-2024-7876 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.7.55 1.6.7.55 2024-10-15 ✓ fixed in latest
CVE-2024-7129 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.43 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') High 7.2 < 1.6.7.43 1.6.7.43 2024-08-23 ✓ fixed in latest
CVE-2024-4288 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.7.18 1.6.7.18 2024-05-15 ✓ fixed in latest
CVE-2024-22311 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.6.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.6.6.24 1.6.6.24 2024-03-26 ✓ fixed in latest
CVE-2024-2342 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.6.7.9 1.6.7.9 2024-03-20 ✓ fixed in latest
CVE-2024-2341 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 1.6.7.9 1.6.7.9 2024-03-20 ✓ fixed in latest
CVE-2024-1760 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.6.24 Cross-Site Request Forgery (CSRF) Medium 4.7 < 1.6.6.24 1.6.6.24 2024-03-05 ✓ fixed in latest
CVE-2023-50851 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.6.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 1.6.6.1 1.6.6.1 2023-12-21 ✓ fixed in latest
CVE-2022-2374 Simply Schedule Appointments [simply-schedule-appointments] < 1.5.7.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.5.7.7 1.5.7.7 2022-08-08 ✓ fixed in latest
CVE-2022-2373 Simply Schedule Appointments [simply-schedule-appointments] < 1.5.7.7 Missing Authorization Medium 5.3 < 1.5.7.7 1.5.7.7 2022-08-08 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.8.7 Improper Control of Generation of Code ('Code Injection') High 7.3 < 1.6.8.7 1.6.8.7 0000-00-00 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.8.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.6.8.32 1.6.8.32 0000-00-00 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.10.2 Unknown < 1.6.10.2 1.6.10.2 0000-00-00 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.10.0 Unknown < 1.6.10.0 1.6.10.0 0000-00-00 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.10.0 Unknown < 1.6.10.0 1.6.10.0 0000-00-00 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29 Unknown < 1.6.9.29 1.6.9.29 0000-00-00 ✓ fixed in latest
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.4 Unknown < 1.6.12.4 1.6.12.4 0000-00-00 ✓ fixed in latest
CVE-2025-1119 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin < 1.6.8.7 - Unauthenticated Arbitrary Shortcode Execution Unknown < 1.6.8.7 1.6.8.7 ✓ fixed in latest
CVE-2025-4667 Simply Schedule Appointments < 1.6.8.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes Unknown < 1.6.8.32 1.6.8.32 ✓ fixed in latest
CVE-2026-1708 Appointment Booking Calendar < 1.6.9.29 - Unauthenticated SQL Injection via 'append_where_sql' Parameter Unknown < 1.6.9.29 1.6.9.29 ✓ fixed in latest
CVE-2026-3045 Appointment Booking Calendar < 1.6.10.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint Unknown < 1.6.10.0 1.6.10.0 ✓ fixed in latest
CVE-2026-1704 Appointment Booking Calendar < 1.6.10.0 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure Unknown < 1.6.10.0 1.6.10.0 ✓ fixed in latest
CVE-2026-3658 Appointment Booking Calendar < 1.6.10.2 - Unauthenticated SQL Injection via 'fields' Parameter Unknown < 1.6.10.2 1.6.10.2 ✓ fixed in latest
CVE-2026-13400 Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information Unknown < 1.6.12.4 1.6.12.4 ✓ fixed in latest

How to fix it

Keep Simply Schedule Appointments updated — 1.6.12.15 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.