Known vulnerabilities in the For Appointments And Events plugin
18 security advisories have been published for the For Appointments And Events plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- For Appointments And Events - Improper Input Validation (CVE-2026-5356) HIGH
- For Appointments And Events - Broken Access Control (CVE-2026-11398) MEDIUM
- For Appointments And Events - Security Vulnerability (CVE-2026-12657) MEDIUM
- For Appointments And Events - Privilege Escalation (CVE-2026-13228) HIGH
- For Appointments And Events - Privilege Escalation (CVE-2026-8176) HIGH
- For Appointments And Events - Cross-Site Request Forgery (CSRF) (CVE-2026-9719) MEDIUM
- For Appointments And Events - Cross-Site Scripting (XSS) (CVE-2026-7332) HIGH
- For Appointments And Events - Privilege Escalation (CVE-2026-6741) HIGH
- For Appointments And Events - Cross-Site Scripting (XSS) (CVE-2026-4785) MEDIUM
- For Appointments And Events - Cross-Site Request Forgery (CSRF) (CVE-2026-2324) MEDIUM
- For Appointments And Events - SQL Injection (CVE-2026-1487) MEDIUM
- For Appointments And Events - Privilege Escalation (CVE-2026-1566) HIGH
- For Appointments And Events - Cross-Site Request Forgery (CSRF) (CVE-2025-14873) MEDIUM
- For Appointments And Events - Broken Access Control (CVE-2026-1537) MEDIUM
- For Appointments And Events - Cross-Site Scripting (XSS) (CVE-2026-0617) HIGH
- For Appointments And Events - Cross-Site Scripting (XSS) (CVE-2025-6941) MEDIUM
- For Appointments And Events - Cross-Site Scripting (XSS) (CVE-2025-6815) MEDIUM
- For Appointments And Events - Security Vulnerability (CVE-2025-3769) MEDIUM