Access Control Flaw in NSquared Simply Schedule Appointments Plugin
CVE-2025-69315
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2025-69315?
A missing authorization vulnerability exists in NSquared Simply Schedule Appointments, specifically affecting versions up to and including 1.6.9.15. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized access to sensitive functionalities within the plugin. It is crucial for users to check their installations and update to a secure version to mitigate risks.
Affected Version(s)
Simply Schedule Appointments 0 <= 1.6.9.15