๐Ÿ” CVE Alert

CVE-2026-15254

UNKNOWN 0.0

Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.

Vendor unknown
Product simply schedule appointments
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simply schedule appointments

Be the first to know when new unknown vulnerabilities affecting unknown simply schedule appointments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simply Schedule Appointments
0 < 1.6.12.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/551554a8-12fb-4eb5-bd24-ae627b58dc3b/

Credits

Meher Sudhakar Abbireddi WPScan