Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability

Vulnerability

A vulnerability allowing unauthenticated arbitrary shortcode execution has been identified in the Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin for WordPress, affecting all versions through 1.6.8.5. The issue arises because the plugin does not properly validate user input before executing shortcodes, allowing attackers to exploit this lack of validation.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, which may be used to inject malicious content or scripts that could be executed within the WordPress environment.

Remediation

Users are advised to update the Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin to version 1.6.8.7 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.