Unrated severityNVD Advisory· Published Aug 2, 2026· Updated Aug 3, 2026
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
CVE-2026-16540
Description
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.6.12.6
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/c3829294-c388-4151-9e25-a3eac7b1f1c6/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.