PatchSiren

NSquared CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM NSquared CVE published 2026-07-13

CVE-2026-59523

The CVE-2026-59523 record describes a Missing Authorization vulnerability in the Simply Schedule Appointments plugin for WordPress. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels and affects the plugin from n/a through <= 1.6.11.11. The CVSS score of 6.5 indicates a Medium severity. Users of the plugin should verify their installations and update to a patched versio [truncated]

MEDIUM NSquared CVE published 2026-07-13

CVE-2026-57812

A Missing Authorization vulnerability was found in the Simply Schedule Appointments plugin for WordPress. This issue, identified as CVE-2026-57812, allows attackers to exploit incorrectly configured access control security levels. The vulnerability affects versions from n/a through 1.6.12.4. The issue arises from a lack of proper authorization checks, potentially allowing unauthorized actions. Users shoul [truncated]

HIGH NSquared CVE published 2026-06-15

CVE-2026-42384

CVE-2026-42384 is a HIGH severity vulnerability (CVSS Score: 7.5) affecting Simply Schedule Appointments plugin versions < 1.6.11.2. The vulnerability is described as Unauthenticated Sensitive Data Exposure.

CRITICAL NSquared CVE published 2026-06-15

CVE-2026-39493

A critical vulnerability was discovered in the Simply Schedule Appointments plugin, affecting versions up to and including 1.6.9.27. This vulnerability, tracked as CVE-2026-39493, is an unauthenticated SQL injection issue with a CVSS score of 9.3, indicating a high severity level. The vulnerability allows attackers to inject malicious SQL code without requiring authentication, potentially leading to unaut [truncated]

HIGH NSquared CVE published 2026-06-15

CVE-2026-39447

A high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability was discovered in Simply Schedule Appointments plugin versions <= 1.6.10.6. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It allows unauthenticated attackers to inject malicious scripts into the application.

MEDIUM NSquared CVE published 2026-04-08

CVE-2026-39694

A Missing Authorization vulnerability was found in Simply Schedule Appointments, allowing for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simply Schedule Appointments versions from n/a through 1.6.10.2. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The CVE record was published on 2026-04-08T09:16:41.783Z and last modified on 2026-0 [truncated]

HIGH NSquared CVE published 2026-04-08

CVE-2026-39495

A SQL injection vulnerability was discovered in the Simply Schedule Appointments plugin for WordPress, affecting versions up to 1.6.9.27. This issue allows for Blind SQL Injection attacks, with a CVSS score of 8.5 and a HIGH severity rating. The vulnerability is caused by improper neutralization of special elements used in SQL commands. Users of the plugin should be aware of this vulnerability and take st [truncated]