CVE-2026-84764
largeUnauthenticated CSRF in WordPress Simply Schedule Appointments Plugin
CVE-2026-84764 is an unauthenticated Cross-Site Request Forgery (CSRF) flaw in the Simply Schedule Appointments booking plugin for WordPress, affecting all versions up to and including 1.6.12.23. An attacker can craft a malicious link or web page that, when viewed by a logged-in site administrator, causes the victim's browser to silently submit unintended state-changing requests to the plugin; the attacker needs no account or credentials on the target site. Successful exploitation lets the attacker trigger privileged actions with the victim's permissions, such as altering plugin or site settings, which the 8.8 (High) CVSS score rates as high impact for confidentiality, integrity, and availability. Any WordPress site running Simply Schedule Appointments 1.6.12.23 or earlier is affected. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS is low (0.1%), so no exploitation is currently known.
What to do: Update Simply Schedule Appointments to the latest patched release (any version above 1.6.12.23) via the WordPress dashboard. Until updated, avoid clicking untrusted links while logged in with administrator privileges, and review recent changes to the plugin's settings and appointment configuration for signs of tampering.
| Nifty (developer of Simply Schedule Appointments) Simply Schedule Appointments (WordPress plugin) | <= 1.6.12.23 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.