๐Ÿ” CVE Alert

CVE-2026-16540

UNKNOWN 0.0

Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.

Vendor unknown
Product simply schedule appointments
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simply schedule appointments

Be the first to know when new unknown vulnerabilities affecting unknown simply schedule appointments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simply Schedule Appointments
0 < 1.6.12.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c3829294-c388-4151-9e25-a3eac7b1f1c6/

Credits

Suleyman Huseynov WPScan