CVE-2026-16541
Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
| Vendor | unknown |
| Product | simply schedule appointments |
| Published | Aug 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown simply schedule appointments
Be the first to know when new unknown vulnerabilities affecting unknown simply schedule appointments are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Simply Schedule Appointments
0 < 1.6.12.17
References
Credits
Yaswanth Reddy Sunkara WPScan