The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 06:17
Updated : 2026-08-26 16:30
NVD link : CVE-2026-16541
Mitre link : CVE-2026-16541
CVE.ORG link : CVE-2026-16541
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
