SuperSaaS – online appointment scheduling
SuperSaaS – online appointment scheduling has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for SuperSaaS – online appointment scheduling has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. SuperSaaS – online appointment scheduling is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-37460SuperSaaS – online appointment scheduling <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

SuperSaaS – online appointment scheduling
Author
supersaas
SuperSaaS is a flexible online appointment scheduling system that works with many different businesses and is available in over 28 languages. The basic version is free, a paid version is available for large users and commercial use. The plugin can automatically log a user into a SuperSaaS schedule using his WordPress username. It passes along the user’s information, creating or updating the user’s information on SuperSaaS as needed. This saves users from having to log in twice. MORE INFORMATION Read the SuperSaaS WordPress Plugin documentation page for information about how to install and setup the plugin in WordPress. Visit the supersaas.com website for an overview of all features of the booking system. Languages SuperSaaS is available in over 28 languages. Check out the SuperSaaS website for more information.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C