Unauthenticated Cross-Site Scripting Vulnerability in Simply Schedule Appointments by Simply Schedule
CVE-2026-39447
7.1HIGH
What is CVE-2026-39447?
The Simply Schedule Appointments plugin for WordPress, specifically in versions up to and including 1.6.10.6, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This flaw can allow attackers to inject malicious scripts into web pages viewed by other users, potentially compromising their session and exposing sensitive data. It is critical for users of affected versions to update their installations promptly to mitigate this security risk.
Affected Version(s)
Simply Schedule Appointments <= 1.6.10.6