Impact
Unauthenticated SQL Injection in Simply Schedule Appointments permits any web user to inject arbitrary SQL into the plugin’s database queries, potentially allowing read, modification, or deletion of appointment data and escalation of privileges. The vulnerability maps to CWE‑89, underscoring the risk of uncontrolled input handling.
Affected Systems
WordPress plugin Simply Schedule Appointments from vendor NSquared, affected versions up through 1.6.9.27. The issue is mitigated in version 1.6.9.29 and later.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical, and while the EPSS score is below 1% indicating low current exploitation probability, the vulnerability is not listed in the KEV catalog. Attackers would likely target the plugin via standard web requests to its unauthenticated endpoints, the attack vector being inferred from the absence of authentication requirements stipulated in the description.
OpenCVE Enrichment