What is CVE-2026-65508?
CVE-2026-65508 is an unauthenticated SQL injection vulnerability found in the Simply Schedule Appointments plugin versions 1.6.12.10 and earlier. An attacker can exploit this flaw to execute unauthorized database queries. Users are advised to update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-65508, Simply Schedule Appointments plaginin 1.6.12.10 və daha əvvəlki versiyalarında aşkarlanan, autentifikasiya tələb etməyən SQL injection zəifliyidir. Bu boşluqdan istifadə edən hücumçu məlumat bazasına icazəsiz sorğular göndərə bilər. İstifadəçilərə plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Simply Schedule Appointments plugin are affected by CVE-2026-65508?
CVE-2026-65508 affects versions 1.6.12.10 and earlier of the Simply Schedule Appointments plugin.
What should be done to mitigate CVE-2026-65508?
Users are advised to update the Simply Schedule Appointments plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.