Description
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross Site Scripting flaw exists in versions of the Simply Schedule Appointments WordPress plugin through and including 1.6.12.10. The vulnerability allows a malicious actor to embed and execute arbitrary client‑side script code within the web page that users view, leading to potential manipulation of the page’s content or behavior. The weakness is a failure to properly sanitize user‑supplied input before rendering it, consistent with CWE‑79.

Affected Systems

WordPress sites that have installed the NSquared Simply Schedule Appointments plugin with a version equal to or older than 1.6.12.10 are vulnerable. The bug is fixed in version 1.6.12.11 and later.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity risk. Because the flaw is unauthenticated, any visitor to the site can trigger the attack, removing the need for additional privileges. The EPSS metric is not available, so the current public exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating that no widely recognized active exploits have been reported at the time of analysis.

Generated by OpenCVE AI on August 6, 2026 at 16:22 UTC.

Remediation

Vendor Solution

Update the WordPress Simply Schedule Appointments Plugin to the latest available version (at least 1.6.12.11).


OpenCVE Recommended Actions

  • Upgrade the Simply Schedule Appointments plugin to version 1.6.12.11 or newer.
  • Remove any older plugin files from the WordPress installation to ensure the vulnerable code is no longer present.
  • Apply a web application firewall or enforce a content security policy that blocks the execution of injected scripts until the patch is applied.

Generated by OpenCVE AI on August 6, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress
Vendors & Products Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
Title WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Nsquared Simply Schedule Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:26.018Z

Reserved: 2026-07-22T08:54:01.673Z

Link: CVE-2026-65513

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')