Impact
The vulnerability is an unauthenticated Cross Site Request Forgery flaw in the Simply Schedule Appointments plugin for WordPress up to version 1.6.12.23. This weakness allows an attacker to craft a request that forces a victim’s browser to perform privileged actions within the plugin on behalf of the victim, potentially creating appointments, modifying settings, or accessing sensitive data. The impact is the loss of integrity and potential data exposure for any user who visits a malicious page while authenticated to the site.
Affected Systems
WordPress installations running the Simply Schedule Appointments plugin version 1.6.12.23 or earlier. The affected product is the NSquared "Simply Schedule Appointments" plugin bundled with WordPress. Patching to at least 1.6.12.24 removes the flaw.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity that could be exploited remotely without authentication. Because the exploit requires only a crafted URL to be visited by an authenticated user, the EPSS was not published but the high CVSS suggests significant risk if the plugin runs on a public website. The vulnerability is not listed in CISA’s KEV catalog, but it remains publicly documented, making discovery likely. Attackers can target any user who has logged into the site and is susceptible to the CSRF request, without needing further intrusion.
OpenCVE Enrichment