PatchSiren cyber security CVE debrief
CVE-2026-16541 Simply Schedule CVE debrief
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This allows low-privileged staff role users to disclose names and email addresses of arbitrary registered users. The vulnerability affects WordPress sites using the Simply Schedule Appointments plugin. To verify, defenders should review user records and REST endpoint access. The CVE record was created based on information from the NVD and a source item. Further details are needed to fully assess the vulnerability.
- Vendor
- Simply Schedule
- Product
- Simply Schedule Appointments
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Administrators of WordPress sites using the Simply Schedule Appointments plugin should verify and restrict access to user records in the plugin's REST endpoints to prevent unauthorized disclosure of registered user information. Additionally, security teams and vulnerability management teams should review the plugin's configuration and user access controls to ensure that they are properly set up to prevent such disclosures.
Technical summary
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see, allowing low-privileged staff role users to disclose names and email addresses of arbitrary registered users. This issue arises from inadequate access controls in the plugin's REST endpoints. Administrators should verify and restrict access to user records in the plugin's REST endpoints to prevent unauthorized disclosure of registered user information. Security teams should review the plugin's configuration and user access controls.
Defensive priority
Verify and restrict access to user records in Simply Schedule Appointments plugin REST endpoints.
Recommended defensive actions
- Verify and restrict access to user records in Simply Schedule Appointments plugin REST endpoints.
- Review and update Simply Schedule Appointments plugin to version 1.6.12.17 or later.
- Monitor user records and REST endpoint access for potential abuse.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was created based on information from the NVD and a source item. Further details are needed to fully assess the vulnerability. The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This could potentially allow low-privileged staff role users to disclose names and email addresses of arbitrary registered users. To verify, defenders should review user records and REST endpoint access.
Official resources
-
CVE-2026-16541 CVE record
CVE.org
-
CVE-2026-16541 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:17:08.280Z and has not been modified since then.