PatchSiren cyber security CVE debrief
CVE-2026-16541 Simply Schedule CVE debrief
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This allows low-privileged staff role users to disclose names and email addresses of arbitrary registered users. The vulnerability affects WordPress sites using the Simply Schedule Appointments plugin. To verify, defenders should review user records and REST endpoint access. The CVE record was created based on information from the NVD and a source item. Further details are needed to fully assess the vulnerability.
- Vendor
- Simply Schedule
- Product
- Simply Schedule Appointments
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-26
Who should care
Administrators of WordPress sites using the Simply Schedule Appointments plugin should verify and restrict access to user records in the plugin's REST endpoints to prevent unauthorized disclosure of registered user information. Additionally, security teams and vulnerability management teams should review the plugin's configuration and user access controls to ensure that they are properly set up to prevent such disclosures.
Technical summary
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see, allowing low-privileged staff role users to disclose names and email addresses of arbitrary registered users. This issue arises from inadequate access controls in the plugin's REST endpoints. Administrators should verify and restrict access to user records in the plugin's REST endpoints to prevent unauthorized disclosure of registered user information. Security teams should review the plugin's configuration and user access controls.
Defensive priority
Verify and restrict access to user records in Simply Schedule Appointments plugin REST endpoints.
Recommended defensive actions
- Verify and restrict access to user records in Simply Schedule Appointments plugin REST endpoints.
- Review and update Simply Schedule Appointments plugin to version 1.6.12.17 or later.
- Monitor user records and REST endpoint access for potential abuse.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was created based on information from the NVD and a source item. Further details are needed to fully assess the vulnerability. The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This could potentially allow low-privileged staff role users to disclose names and email addresses of arbitrary registered users. To verify, defenders should review user records and REST endpoint access.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16541 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16541
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16541 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16541
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/8172f778-5dc5-49e8-9967-81215ac187d7/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.