Impact
Simply Schedule Appointments for WordPress before version 1.6.12.11 does not perform a capability check on an administrative appointment‑listing shortcode, and the shortcode’s result scoping fails open for non‑staff users. The flaw allows users with the Contributor role or higher to retrieve all customers’ appointment data, including names, e‑mail addresses, phone numbers, and notes, for the entire site. The vulnerability therefore exposes confidential customer information without requiring elevated privileges beyond the Contributor role.
Affected Systems
Simply Schedule Appointments plugin for WordPress, versions 1.6.12.10 and earlier. The issue does not affect newer releases starting with 1.6.12.11.
Risk and Exploitability
The flaw is a direct data disclosure and can be exploited by sending a simple web request to the vulnerable shortcode. Only a Contributor role or higher is required, so an attacker who can obtain any Contributor credentials can fully expose sensitive customer information. The EPSS score of < 1% indicates a very low probability of exploitation, but the lack of access controls still creates a high risk of unauthorized data exposure if a Contributor account is compromised or misused. The CVSS score is 6.5.
OpenCVE Enrichment