CVE Database /
CVE-2026-16541
CVE
CVE-2026-16541 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.17
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-16541
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.17 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 1.6.12.17
|
1.6.12.17 |
2026-08-15 |
—
|
CVE-2026-16541
The Simply Schedule Appointments WordPress plugin prior to version 1.6.12.17 has a security flaw that allows users with limited access to view sensitive information about other registered users. Specifically, the plugin's REST endpoints do not properly restrict access to user data, enabling users with a lower staff role to obtain the names and email addresses of other users, potentially revealing sensitive information.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings