CyberRota Analysis
AI-GeneratedThe Simply Schedule Appointments plugin for WordPress prior to version 1.6.12.17 is vulnerable due to insufficient access controls on its REST endpoints, enabling low-privileged users to access and disclose the names and email addresses of other registered users. This exposure can lead to privacy breaches and potential phishing attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.