Impact
Unauthenticated SQL injection exists in WordPress Simply Schedule Appointments plugin versions up to 1.6.12.10. The flaw (CWE‑89) allows an attacker to inject arbitrary SQL through unsanitized input, potentially leading to disclosure, modification, or deletion of database contents. The impact is the ability to read sensitive data or alter the appointment scheduling data without needing credentials.
Affected Systems
NSquared Simply Schedule Appointments plugin for WordPress. All installations using version 1.6.12.10 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity vulnerability. The absence of an EPSS score means no publicly available estimate of exploit probability, but the lack of authentication requirement suggests exploitation is straightforward for an adversary with network access to the website. Since the flaw allows direct manipulation of the SQL server, the risk to confidentiality and integrity of the site’s data is significant. The plugin is not listed in CISA’s KEV catalog, but users should treat it as a high‑risk issue due to the nature of the vulnerability.
OpenCVE Enrichment