
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3658 is an unauthenticated SQL Injection vulnerability in the "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin" for WordPress. It affects all versions up to and including 1.6.10.0, where insufficient escaping of the fields parameter and lack of proper SQL query preparation allow unauthenticated attackers to extract sensitive data from the database. The vulnerability was published on March 19, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability exists in multiple files within the plugin, including class-td-db-model.php (line 1171), class-td-api-model.php (line 140), and class-appointment-type-model.php (line 907), where user-supplied input via the fields parameter is not properly sanitized or parameterized before being incorporated into SQL queries. An unauthenticated remote attacker can append malicious SQL clauses to existing queries, enabling blind or direct SQL injection without any authentication or user interaction. The fix was introduced in changeset 3485143 of the plugin's SVN repository (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, including usernames, email addresses, and password hashes. While the vulnerability's scope is limited to confidentiality (no integrity or availability impact), compromised password hashes could enable credential cracking and subsequent account takeover, potentially leading to full site compromise if administrator credentials are recovered. The impact is confined to the database of the affected WordPress installation (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.075% (0.000750), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It has been detected by Qualys scanners (detection ID 531160), and the low attack complexity combined with no authentication requirement makes it accessible to a wide range of attackers if targeted (Wordfence, Feedly).
fields parameter, which is exposed without authentication.fields parameter value (e.g., using UNION-based or time-based blind injection techniques) to manipulate the underlying SQL query.wp_users containing usernames, email addresses, and hashed passwords.', --, UNION, SELECT, SLEEP) in the fields parameter; high volume of requests to appointment booking endpoints from a single IP.wp_users or other sensitive tables originating from the web application process; database error logs showing SQL syntax errors from malformed injection attempts.Users should update the Simply Schedule Appointments plugin to a version beyond 1.6.10.0, as the vulnerability was patched in changeset 3485143. If immediate updating is not possible, consider disabling the plugin until a patch can be applied, or implement a web application firewall (WAF) rule to block requests containing SQL injection patterns in the fields parameter. Regularly audit WordPress plugin versions and apply updates promptly to minimize exposure (Wordfence, WordPress Trac).
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 16–22, 2026, noting it as a significant unauthenticated SQL injection risk (Wordfence Blog). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). Social media activity was observed on Mastodon and Bluesky, primarily from security aggregator accounts sharing the CVE details, with no notable researcher controversy or debate.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."