Description
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
Published: 2026-09-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Request Forgery flaw in the Simply Schedule Appointments plugin for WordPress up to version 1.6.12.23. This weakness allows an attacker to craft a request that forces a victim’s browser to perform privileged actions within the plugin on behalf of the victim, potentially creating appointments, modifying settings, or accessing sensitive data. The impact is the loss of integrity and potential data exposure for any user who visits a malicious page while authenticated to the site.

Affected Systems

WordPress installations running the Simply Schedule Appointments plugin version 1.6.12.23 or earlier. The affected product is the NSquared "Simply Schedule Appointments" plugin bundled with WordPress. Patching to at least 1.6.12.24 removes the flaw.

Risk and Exploitability

The CVSS score of 8.8 signals a high severity that could be exploited remotely without authentication. Because the exploit requires only a crafted URL to be visited by an authenticated user, the EPSS was not published but the high CVSS suggests significant risk if the plugin runs on a public website. The vulnerability is not listed in CISA’s KEV catalog, but it remains publicly documented, making discovery likely. Attackers can target any user who has logged into the site and is susceptible to the CSRF request, without needing further intrusion.

Generated by OpenCVE AI on September 2, 2026 at 12:22 UTC.

Remediation

Vendor Solution

Update the WordPress Simply Schedule Appointments Plugin to the latest available version (at least 1.6.12.24).


OpenCVE Recommended Actions

  • Update the Simply Schedule Appointments plugin to version 1.6.12.24 or newer
  • If an update cannot be applied immediately, deactivate or remove the plugin to block the vulnerability
  • Deploy web‑application firewall rules to detect and reject unexpected form submissions that lack proper CSRF tokens to mitigate the attack surface while the plugin is inactive

Generated by OpenCVE AI on September 2, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress
Vendors & Products Nsquared
Nsquared simply Schedule Appointments
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
Title WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Nsquared Simply Schedule Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-02T11:37:33.808Z

Reserved: 2026-09-02T09:57:42.761Z

Link: CVE-2026-84764

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:14.800

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T12:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)