Eklenti güvenlik geçmişi
Simply Schedule Appointments güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Simply Schedule Appointments eklentisi için 37 açık kaydı bulunuyor; en yenisi 1 Ekim 2026 tarihli. Bunların 17 tanesi kritik veya yüksek önemde, 27 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 1.6.12.33.
- Toplam kayıt
- 37
- Kritik veya yüksek
- 17
- Oturumsuz istismar
- 27
- Son kayıt
- 1 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
hassas bilgi ifşası
Etkilenen sürümler: 1.6.12.32 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen “Simply Schedule Appointments” eklentisi, 1.6.12.32 sürümü dahil olmak üzere tüm sürümlerinde “recursive” parametresi yoluyla Hassas Bilgilerin Açığa Çıkması güvenlik açığına maruz kalmaktadır. Bu durum, kimliği doğrulanmamış saldırganların randevu kayıtlarında depolanan isimler, e-posta adresleri, telefon numaraları ve özel form alanı verileri dahil olmak üzere müşterilerin kişisel tanımlayıcı bilgilerini (PII) ve randevu başına public_token değerlerini elde etmesine olanak tanır. Sızan randevu başına public_token değerleri, kimlik doğrulaması yapılmamış saldırganların, tek yetkilendirme olarak bu tokeni kabul eden DELETE /wp-json/ssa/v1/appointments/{id} uç noktası aracılığıyla istedikleri randevuları silmelerine de olanak tanır.
Türkçe kayıt ve ne yapmalıyetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.6.12.31 ve öncesi
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose every co-booker's private per-appointment id_token (exposed as public_token) alongside their PII (name and email address), then use each leaked token to read, overwrite arbitrary appointment meta on, or cancel the co-booker's appointment via the same REST controller. Exploitation requires the attacker to possess a valid id_token for any single appointment within the targeted group booking.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.6.12.31 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
eksik yetki denetimi
Etkilenen sürümler: 1.6.12.29 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
yerel dosya dahil etme (LFI)
Etkilenen sürümler: 1.6.12.27 ve öncesi
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value.
Türkçe kayıt ve ne yapmalısiteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 1.6.12.23 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.6.12.10 ve öncesi
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to access appointment records belonging to arbitrary users and harvest the per-appointment ownership tokens (32-character hashes) embedded in the rendered HTML, which can then be used without any authentication to read or modify those appointments including full customer PII such as name, email, phone number, and private notes. The /wp-json/ssa/v1/render-shortcode REST endpoint is registered unconditionally on rest_api_init regardless of whether the Divi theme is installed, and its permission callback only requires current_user_can('edit_posts'), meaning any Contributor-level account is sufficient to trigger this entire exploit chain.
hassas bilgi ifşası
Etkilenen sürümler: 1.6.12.17 öncesi
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.12.10 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
SQL enjeksiyonu
Etkilenen sürümler: 1.6.12.10 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
eksik yetki denetimi
Etkilenen sürümler: 1.6.12.11 öncesi
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.
eksik yetki denetimi
Etkilenen sürümler: 1.6.12.6 öncesi · Oturum açmadan istismar edilebilir
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
eksik yetki denetimi
Etkilenen sürümler: 1.6.11.11 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
eksik yetki denetimi
Etkilenen sürümler: 1.6.12.4 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.12.2 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
hassas bilgi ifşası
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
SQL enjeksiyonu
Etkilenen sürümler: 1.6.9.27 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.10.6 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
eksik yetki denetimi
Etkilenen sürümler: 1.6.11.8 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint. This makes it possible for unauthenticated attackers to modify arbitrary appointment records including customer PII, payment status, and meeting URL fields, and to expose full customer PII from existing appointment records via the bulk endpoint response. The public nonce is a static, user-independent value present in the HTML source of any page hosting the [ssa_booking] shortcode, meaning any visitor who has viewed such a page can obtain it and target any appointment in the system without authentication.
SQL enjeksiyonu
Etkilenen sürümler: 1.6.11.8 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The /appointments/bulk REST endpoint is reachable by unauthenticated attackers because its permission check accepts a public nonce that is embedded in the booking widget's frontend JavaScript (ssa.api.public_nonce) and visible to all site visitors; exploitation requires issuing the request as a PUT with an application/x-www-form-urlencoded body so that PHP's superglobals are not populated and the blocklist check silently passes.
hizmet dışı bırakma (DoS)
Etkilenen sürümler: 1.6.11.5 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied delay parameter without any rate limiting. This makes it possible for unauthenticated attackers to exhaust PHP worker processes, denying access to the site to legitimate users.
eksik yetki denetimi
Etkilenen sürümler: 1.6.10.2 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.
SQL enjeksiyonu
Etkilenen sürümler: 1.6.9.27 ve öncesi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
SQL enjeksiyonu
Etkilenen sürümler: 1.6.10.0 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, including usernames, email addresses, and password hashes.
eksik yetki denetimi
Etkilenen sürümler: 1.6.9.29 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users through the public `/wp-json/ssa/v1/embed-inner` REST endpoint, and (2) the `get_item()` method in `SSA_Settings_Api` relies on `nonce_permissions_check()` for authorization (which accepts the public nonce) but does not call `remove_unauthorized_settings_for_current_user()` to filter restricted fields. This makes it possible for unauthenticated attackers to access admin-only plugin settings including the administrator email, phone number, internal access tokens, notification configurations, and developer settings via the `/wp-json/ssa/v1/settings/{section}` endpoint. The exposure of appointment tokens also allows an attacker to modify or cancel appointments.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.6.9.29 ve öncesi
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments` capability without validating staff ownership of the requested appointment. This makes it possible for authenticated attackers, with custom-level access and above (users granted the ssa_manage_appointments capability, such as Team Members), to view appointment records belonging to other staff members and access sensitive customer personally identifiable information via the appointment ID parameter.
SQL enjeksiyonu
Etkilenen sürümler: 1.6.9.27 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent the `append_where_sql` parameter from being passed through JSON request bodies, while only checking for its presence in the `$_REQUEST` superglobal. This makes it possible for unauthenticated attackers to append arbitrary SQL commands to queries and extract sensitive information from the database via the `append_where_sql` parameter in JSON payloads granted they have obtained a valid `public_token` that is inadvertently exposed during the booking flow.
eksik yetki denetimi
Etkilenen sürümler: 1.6.9.15 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.
hassas bilgi ifşası
Etkilenen sürümler: 1.6.9.16 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, which leaks plugin settings including staff names, business names, and configuration data that are not publicly displayed on the booking form. This makes it possible for unauthenticated attackers to extract private business configuration. In premium versions with integrations configured, this might also expose other sensitive data including API keys for external services.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.8.30 ve öncesi
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
uzaktan kod çalıştırma
Etkilenen sürümler: 1.6.8.5 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.8.3 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.7.14 ve öncesi
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.6.6.20 ve öncesi · Oturum açmadan istismar edilebilir
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N Squared Simply Schedule Appointments allows Reflected XSS.This issue affects Simply Schedule Appointments: from n/a through 1.6.6.20.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 1.6.6.20 ve öncesi · Oturum açmadan istismar edilebilir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.5.7.7 öncesi
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
eksik yetki denetimi
Etkilenen sürümler: 1.5.7.7 öncesi · Oturum açmadan istismar edilebilir
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Türkçe açıklamalar makine çevirisidir; bağlayıcı metin NVD’deki İngilizce kayıttır. Veri 7 Ekim 2026 itibarıyla.