HIGH
CVE-2026-16540
CVSS
7.5
Description
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.42%
Probability of exploitation in next 30 days
35.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.