Impact
The vulnerability allows an unauthenticated attacker to read sensitive data exposed by the Simply Schedule Appointments plugin when it is running a version earlier than 1.6.11.2. The weakness is a classic sensitive data exposure flaw (CWE‑201) that can compromise the confidentiality of private scheduling information and potentially other data that the plugin processes. Because no authentication is required, the impact is potentially global across all sites using a vulnerable instance of the plugin.
Affected Systems
This flaw affects the NSquared Simply Schedule Appointments WordPress plugin on any WordPress installation where the plugin version is lower than 1.6.11.2. The vendor does not specify additional platform constraints, so any WordPress site that has installed a pre‑1.6.11.2 release is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by accessing exposed plugin endpoints over the Internet without credentials, making the attack pathway straightforward. Although the likelihood of exploitation is low right now, the potential damage to confidentiality makes it prudent to address promptly.
OpenCVE Enrichment