CVE-2026-16540 - Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
CVE ID :CVE-2026-16540
Published : Aug. 2, 2026, 6:16 a.m. | 37 minutes ago
Description :The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 2, 2026, 6:16 a.m. | 37 minutes ago
Description :The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...