Detects WordPress installs running the Simply Schedule Appointments plugin at version 1.6.10.0 or earlier. The plugin's TD_DB_Model::db_query() method takes the fields[] parameter from REST API requests and interpolates values directly into the SQL SELECT clause via backtick-wrapped implode() without sanitization or allowlist validation. An unauthenticated attacker can inject SQL to extract usernames, email addresses, and password hashes from the WordPress database.
Is your app exploitable through CVE-2026-3658?
Scan your domain free