Missing Authorization Vulnerability in NSquared Simply Schedule Appointments
CVE-2026-39694
5.3MEDIUM
What is CVE-2026-39694?
A missing authorization vulnerability in the NSquared Simply Schedule Appointments plugin allows attackers to exploit incorrectly configured access control security levels, potentially granting unauthorized access to sensitive features. The issue impacts all versions of the plugin up to 1.6.10.2, making it crucial for users to assess their security settings and apply necessary updates.
Affected Version(s)
Simply Schedule Appointments 0 <= 1.6.10.2