๐Ÿ” CVE Alert

CVE-2026-16541

UNKNOWN 0.0

Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.

Vendor unknown
Product simply schedule appointments
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simply schedule appointments

Be the first to know when new unknown vulnerabilities affecting unknown simply schedule appointments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simply Schedule Appointments
0 < 1.6.12.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8172f778-5dc5-49e8-9967-81215ac187d7/

Credits

Yaswanth Reddy Sunkara WPScan