Back to CVE List

CVE-2026-13400

Vulnerability Description

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Simply Schedule Appointments

External References

Discussion (0)

Add Comment

No comments yet. Be the first!