A vulnerability was found in Simply Schedule Appointments Plugin up to 1.6.12.2 on WordPress and classified as problematic. Impacted is the function wp_kses_post of the component Notification Rendering. Such manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2026-13400. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.