CVE-2026-16541

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-15 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-16541

Mitre link : CVE-2026-16541

CVE.ORG link : CVE-2026-16541


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor