Impact
The Simply Schedule Appointments WordPress plugin versions before 1.6.12.17 fails to enforce proper authorization on its REST endpoints. As a result, a user with a low‑privileged staff role can issue API requests that return the names and email addresses of any registered user in the system. This flaw allows an attacker who has limited access privileges to obtain sensitive personal information belonging to arbitrary users.
Affected Systems
WordPress installations running the Simply Schedule Appointments plugin any version earlier than 1.6.12.17 are affected. The vulnerability manifests in the plugin’s Users and Customers REST endpoints and applies to all sites where the plugin is activated.
Risk and Exploitability
Because the flaw is accessed through standard REST API calls, the likely attack vector involves a low‑privilege account already authenticated to the WordPress site. No CVSS score is provided, and EPSS data is unavailable; the vulnerability is not listed in the CISA KEV catalog. The risk is moderate: an attacker can retrieve personal data without needing elevated privileges, but cannot alter, delete, or exfiltrate data beyond what the API returns. The impact is limited to identity exposure rather than broader system compromise.
OpenCVE Enrichment