SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15254

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Simply Schedule Appointments plugin for WordPress versions prior to 1.6.12.11 is vulnerable due to inadequate capability checks on an administrative shortcode, allowing users with Contributor roles and higher to access sensitive customer appointment records site-wide. This exposure can lead to unauthorized disclosure of personal information, including names, email addresses, and phone numbers. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-15254
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%
WordPress

Original NVD Description

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.