CVE-2026-13400

Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.


We have discovered 6,078 live websites that are affected by CVE-2026-13400.

Run a Free Instant Scan




Affected Software

Product  Simply Schedule Appointments
Category Wordpress Plugins
Vulnerable Domains6,078 live websites (80% of Simply Schedule Appointments install base)
Vulnerable Versions
  • from 0 through 1.6.12.4
Vulnerable Versions Count162 versions ( 46% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Revanth Hari Narayana Matte (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-13400
United States1,723 websites



Germany1,234 websites
Italy365 websites
GB297 websites
Netherlands236 websites
France228 websites
Spain166 websites
Canada162 websites
Denmark130 websites
Switzerland109 websites

Website Distribution by TLD

Number of websites using CVE-2026-13400
.com2,485 websites
.de892 websites
.it265 websites
.org222 websites
.nl211 websites
.co.uk173 websites
.net131 websites
.fr102 websites
.ch100 websites
.ca93 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13400

Top websites that are affected by CVE-2026-13400. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.org United States**,***
*********.org United States**,***
*****************.org GB***,***
****************.org United States***,***
*******.com GB***,***
****.hu Hungary***,***
***************.com India***,***
**************.com United States***,***
***********.com United States***,***
******.***.edu United States***,***
See full domain list

FAQ

CVE-2026-13400 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Simply Schedule Appointments
A total of 6,078 websites have been identified as vulnerable to CVE-2026-13400, based on global website indexing conducted by WebTechSurvey.
The Simply Schedule Appointments is affected by the CVE-2026-13400 vulnerability.
Simply Schedule Appointments versions up to 1.6.12.4 are vulnerable to CVE-2026-13400.
CVE-2026-13400 is resolved in version 1.6.12.4 of Simply Schedule Appointments.