CVE-2026-16541
Deferred Deferred - Pending Action

Unauthorized User Data Exposure in Simply Schedule Appointments WordPress Plugin

Vulnerability report for CVE-2026-16541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-26
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simply_schedule_appointments simply_schedule_appointments to 1.6.12.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Simply Schedule Appointments WordPress plugin before version 1.6.12.17. It allows users with a low-privileged staff role to access REST endpoints that return user records without proper restrictions. This means they can view the names and email addresses of any registered users, even those they shouldn't have permission to see.

Detection Guidance

To detect this vulnerability, check if your Simply Schedule Appointments plugin version is below 1.6.12.17. You can verify the version via WordPress admin panel under Plugins or by inspecting the plugin files. Test the affected REST endpoints by sending requests to /wp-json/ss/v1/users or similar paths with a low-privileged staff account to see if unauthorized user data is returned.

Impact Analysis

If you use the Simply Schedule Appointments plugin with a version prior to 1.6.12.17, a low-privileged user on your site could exploit this flaw to steal personal data like names and email addresses of other users. This could lead to privacy breaches or be used for phishing attacks.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and other privacy regulations by exposing personal data without authorization. GDPR requires protecting personal data, and such breaches may result in fines or legal consequences.

Mitigation Strategies

Immediately update the Simply Schedule Appointments plugin to version 1.6.12.17 or later. If an update is not available, consider disabling the plugin temporarily until a patch is released. Review user roles and permissions to ensure low-privileged staff accounts do not have unnecessary access to sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart