CVE-2026-65508: Unauthenticated SQL Injection in Simply Schedule Appointments Plugin
A critical vulnerability (CVE-2026-65508, CVSS 9.3) was discovered in the Simply Schedule Appointments plugin (versions <= 1.6.12.10) for WordPress, allowing unauthenticated SQL injection. This flaw can be exploited remotely without authentication, posing a significant risk to affected installations. Immediate action is required to update to a patched version.