CVE-2024-7876
- EPSS 0.15%
- Veröffentlicht 05.11.2024 06:15:05
- Zuletzt bearbeitet 06.11.2024 15:42:37
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-...
CVE-2024-7877
- EPSS 0.2%
- Veröffentlicht 05.11.2024 06:15:05
- Zuletzt bearbeitet 06.11.2024 15:42:19
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site...
CVE-2024-7129
- EPSS 15.59%
- Veröffentlicht 13.09.2024 06:15:15
- Zuletzt bearbeitet 15.09.2025 20:15:35
The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins
CVE-2023-50851
- EPSS 0.14%
- Veröffentlicht 28.12.2023 12:15:43
- Zuletzt bearbeitet 21.11.2024 08:37:24
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N Squared Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin.This issue affects Appointment Booking Calendar — Simply Schedu...
CVE-2022-2373
- EPSS 8.39%
- Veröffentlicht 29.08.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:51
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
CVE-2022-2374
- EPSS 0.36%
- Veröffentlicht 29.08.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:51
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capa...