Description
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Published: 2026-08-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Simply Schedule Appointments WordPress plugin prior to version 1.6.12.6, where a bulk appointment operation fails to enforce proper requestor ownership checks. The result is that any user, even unauthenticated, can retrieve the personal data of every scheduled appointment across the entire site, and on premium editions can permanently delete all appointments. This allows an attacker to compromise confidentiality by reading all appointment data and to compromise integrity by removing all records, potentially causing loss of service or data loss to users. The weakness reflects broken access control and sensitive data exposure, classified as CWE-863.

Affected Systems

All WordPress sites that use the Simply Schedule Appointments plugin with a version earlier than 1.6.12.6, regardless of the installation environment or user roles. The issue appears on both free and premium editions, but the deletion capability is only available on the premium line.

Risk and Exploitability

The EPSS score of less than 1% suggests that, on average, this vulnerability is unlikely to be actively exploited, and it is not listed in the CISA KEV catalog. However, the flaw is exploitable by anyone with network access to the site, requiring no authentication. An attacker can simply query the purge or bulk appointment endpoints to read or delete data. The attack vector is presumed to be a standard HTTP request to the plugin’s REST API endpoints, executed by an unauthenticated client. The CVSS score is 7.5, indicating a high severity vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Simply Schedule Appointments plugin to version 1.6.12.6 or later, which corrects the missing access restrictions.
  • Configure the web server or an application firewall to deny unauthenticated requests to the plugin’s bulk operation or purge REST API endpoints (e.g., /wp-json/schedule/v1/*).
  • Review WordPress user roles and permissions, ensuring only authorized users have high‑privilege appointment access, and audit existing appointments for correct data handling.

Generated by OpenCVE AI on August 4, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Nsqua
Nsqua simply Schedule Appointments
Wordpress
Wordpress wordpress
Vendors & Products Nsqua
Nsqua simply Schedule Appointments
Wordpress
Wordpress wordpress

Tue, 04 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-862

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-862

Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Title Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
References

Subscriptions

Nsqua Simply Schedule Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-03T17:49:00.837Z

Reserved: 2026-07-22T09:38:49.604Z

Link: CVE-2026-16540

cve-icon Vulnrichment

Updated: 2026-08-03T17:48:56.437Z

cve-icon NVD

Status : Received

Published: 2026-08-02T06:16:40.950

Modified: 2026-08-03T19:16:44.427

Link: CVE-2026-16540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:45:07Z

Weaknesses