Impact
An unauthenticated Cross Site Scripting flaw exists in versions of the Simply Schedule Appointments WordPress plugin through and including 1.6.12.10. The vulnerability allows a malicious actor to embed and execute arbitrary client‑side script code within the web page that users view, leading to potential manipulation of the page’s content or behavior. The weakness is a failure to properly sanitize user‑supplied input before rendering it, consistent with CWE‑79.
Affected Systems
WordPress sites that have installed the NSquared Simply Schedule Appointments plugin with a version equal to or older than 1.6.12.10 are vulnerable. The bug is fixed in version 1.6.12.11 and later.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity risk. Because the flaw is unauthenticated, any visitor to the site can trigger the attack, removing the need for additional privileges. The EPSS metric is not available, so the current public exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating that no widely recognized active exploits have been reported at the time of analysis.
OpenCVE Enrichment