Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw that allows an attacker to inject malicious JavaScript into the plugin’s pages. If exploited, arbitrary code could run in the context of any user who views the affected content, enabling actions such as cookie theft, session hijacking, or defacement. The flaw falls under CWE‑79, indicating unsanitized input handling.
Affected Systems
This issue affects the WordPress Simply Schedule Appointments plugin developed by NSquared. All releases up to and including version 1.6.10.6 are impacted. Higher versions, starting with 1.6.11.0, contain the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderately high risk. The EPSS score is less than 1 percent, suggesting a low likelihood of widespread exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Since the flaw is unauthenticated, an attacker can trigger it by forging a request without logging in, so the attack vector is likely to be a simple HTTP request to a vulnerable endpoint or form field.
OpenCVE Enrichment