ZeroHour

CVE-2026-84764

large

Unauthenticated CSRF in WordPress Simply Schedule Appointments Plugin

CVSS 3.1
8.8 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-84764 is an unauthenticated Cross-Site Request Forgery (CSRF) flaw in the Simply Schedule Appointments booking plugin for WordPress, affecting all versions up to and including 1.6.12.23. An attacker can craft a malicious link or web page that, when viewed by a logged-in site administrator, causes the victim's browser to silently submit unintended state-changing requests to the plugin; the attacker needs no account or credentials on the target site. Successful exploitation lets the attacker trigger privileged actions with the victim's permissions, such as altering plugin or site settings, which the 8.8 (High) CVSS score rates as high impact for confidentiality, integrity, and availability. Any WordPress site running Simply Schedule Appointments 1.6.12.23 or earlier is affected. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS is low (0.1%), so no exploitation is currently known.

What to do: Update Simply Schedule Appointments to the latest patched release (any version above 1.6.12.23) via the WordPress dashboard. Until updated, avoid clicking untrusted links while logged in with administrator privileges, and review recent changes to the plugin's settings and appointment configuration for signs of tampering.

Affected
Nifty (developer of Simply Schedule Appointments) Simply Schedule Appointments (WordPress plugin)<= 1.6.12.23
Estimated exposure
largetens of thousands of WordPress sites (plugin has roughly 20,000-30,000 active installs on WordPress.org) — The estimate is based on the plugin's WordPress.org active-install count, in the tens of thousands, with the actual affected subset limited to sites running version 1.6.12.23 or older and to admins who are tricked into clicking…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.