CVE-2026-4807
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
Minimum safe version
1.6.11.2
Update to 1.6.11.2 or later to address 27 fixable vulnerabilities
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin < 1.6.11.2 - Unauthenticated Sensitive Information Exposure
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.27 - Unauthenticated SQL Injection
Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure
Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint
Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter
CVE-2026-39694
CVE-2026-39495
CVE-2025-69315
CVE-2025-12166
CVE-2025-11723
CVE-2025-13754
Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution
CVE-2024-13431
CVE-2024-7876
CVE-2024-7877
CVE-2024-7129
CVE-2024-4288
CVE-2024-22311
CVE-2024-2341
CVE-2024-2342
CVE-2024-1760
WordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL Injection
CVE-2022-2373
CVE-2022-2374