CVE Database /
CVE-2022-2373
CVE · Medium
CVE-2022-2373 — Simply Schedule Appointments [simply-schedule-appointments] < 1.5.7.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2373
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.5.7.7 |
Missing Authorization |
Medium
5.3
|
< 1.5.7.7
|
1.5.7.7 |
2022-08-08 |
—
|
CVE-2022-2373
The Simply Schedule Appointments plugin through version 1.5.7.5 contains a sensitive information disclosure vulnerability affecting its /wp-json/ssa/v1/users REST API endpoint. Unauthenticated attackers can exploit the lack of proper access controls to retrieve email addresses of registered site users. This flaw was fixed in version 1.5.7.7.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings