cleantalk
Vulnerabilities and Security Researches

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin, CVE-2026-16541

CVE, Research URL

CVE-2026-16541

Published on
Aug 15, 2026
Research Description
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
Affected versions
max 1.6.12.17.
Status
vulnerable