What is CVE-2026-13400?
The Simply Schedule Appointments plugin contains an unauthenticated Stored Cross-Site Scripting vulnerability affecting versions up to and including 1.6.12.2. The issue stems from a sanitization-ordering defect where rendered notification content is decoded back into live HTML, allowing malicious scripts to be injected. Users should update to the latest patched version immediately.
Azərbaycanca: Simply Schedule Appointments plaqinində autentifikasiya olunmamış saxlanılan XSS (Stored Cross-Site Scripting) zəifliyi aşkarlanıb. Bu boşluq 1.6.12.2 daxil olmaqla bütün əvvəlki versiyalara təsir edir və xüsusi hazırlanmış bildiriş məzmunu vasitəsilə icra olunur. İstifadəçilər dərhal plaqini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Simply Schedule Appointments plugin are affected by CVE-2026-13400?
The vulnerability affects all versions up to and including 1.6.12.2.
What should users do to protect themselves from CVE-2026-13400?
Users should immediately update the plugin to the latest patched version or temporarily deactivate it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.