HIGH

CVE-2026-16540

2026-08-02 CVSS v3.1
CVSS
7.5

Description

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.42%
Probability of exploitation in next 30 days
35.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE