CVE-2026-15254
Received Received - Intake

Unauthenticated Customer Data Exposure in Simply Schedule Appointments WordPress Plugin

Vulnerability report for CVE-2026-15254, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simply_schedule_appointments simply_schedule_appointments to 1.6.12.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Simply Schedule Appointments WordPress plugin before version 1.6.12.11. It allows users with the Contributor role or higher to access all appointment records across the site, including sensitive customer data like names, email addresses, phone numbers, and notes.

Detection Guidance

Check if the Simply Schedule Appointments WordPress plugin version is below 1.6.12.11. Log in as a Contributor role user and attempt to access appointment records via the affected shortcode. Review server logs for unauthorized access attempts to appointment data.

Impact Analysis

If exploited, this vulnerability could expose your customers' personal information, leading to privacy breaches, identity theft risks, and potential legal consequences. It undermines trust in your service and may result in reputational damage.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and HIPAA if health-related appointment data is exposed. It can lead to non-compliance penalties, legal actions, and mandatory breach notifications.

Mitigation Strategies

Update the Simply Schedule Appointments plugin to version 1.6.12.11 or later immediately. Review user roles and permissions to ensure only authorized staff can access appointment data. Consider temporarily disabling the plugin until updated if immediate patching is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15254. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart