CVE · Medium

CVE-2022-2373 — Simply Schedule Appointments [simply-schedule-appointments] < 1.5.7.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2373 Simply Schedule Appointments [simply-schedule-appointments] < 1.5.7.7 Missing Authorization Medium 5.3 < 1.5.7.7 1.5.7.7 2022-08-08

CVE-2022-2373

The Simply Schedule Appointments plugin through version 1.5.7.5 contains a sensitive information disclosure vulnerability affecting its /wp-json/ssa/v1/users REST API endpoint. Unauthenticated attackers can exploit the lack of proper access controls to retrieve email addresses of registered site users. This flaw was fixed in version 1.5.7.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.