CVE

CVE-2026-16541 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16541 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.17 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 1.6.12.17 1.6.12.17 2026-08-15

CVE-2026-16541

The Simply Schedule Appointments WordPress plugin prior to version 1.6.12.17 has a security flaw that allows users with limited access to view sensitive information about other registered users. Specifically, the plugin's REST endpoints do not properly restrict access to user data, enabling users with a lower staff role to obtain the names and email addresses of other users, potentially revealing sensitive information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.