Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.
We have discovered 6,078 live websites that are affected by CVE-2026-13400.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 6,078 live websites (80% of Simply Schedule Appointments install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 162 versions ( 46% of all versions) |
| 1,723 websites | |
| 1,234 websites | |
| 365 websites | |
| 297 websites | |
| 236 websites | |
| 228 websites | |
| 166 websites | |
| 162 websites | |
| 130 websites | |
| 109 websites |
| .com | 2,485 websites |
| .de | 892 websites |
| .it | 265 websites |
| .org | 222 websites |
| .nl | 211 websites |
| .co.uk | 173 websites |
| .net | 131 websites |
| .fr | 102 websites |
| .ch | 100 websites |
| .ca | 93 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.org | **,*** | ||
| *********.org | **,*** | ||
| *****************.org | ***,*** | ||
| ****************.org | ***,*** | ||
| *******.com | ***,*** | ||
| ****.hu | ***,*** | ||
| ***************.com | ***,*** | ||
| **************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ******.***.edu | ***,*** |
FAQ