CVE-2026-16540
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
| Vendor | unknown |
| Product | simply schedule appointments |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown simply schedule appointments
Be the first to know when new unknown vulnerabilities affecting unknown simply schedule appointments are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Simply Schedule Appointments
0 < 1.6.12.6
References
Credits
Suleyman Huseynov WPScan