AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16541

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Simply Schedule Appointments plugin for WordPress prior to version 1.6.12.17 is vulnerable due to insufficient access controls on its REST endpoints, enabling low-privileged users to access and disclose the names and email addresses of other registered users. This exposure can lead to privacy breaches and potential phishing attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-16541
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.