PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16541 Simply Schedule CVE debrief

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This allows low-privileged staff role users to disclose names and email addresses of arbitrary registered users. The vulnerability affects WordPress sites using the Simply Schedule Appointments plugin. To verify, defenders should review user records and REST endpoint access. The CVE record was created based on information from the NVD and a source item. Further details are needed to fully assess the vulnerability.

Vendor
Simply Schedule
Product
Simply Schedule Appointments
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-26
Advisory published
2026-08-15
Advisory updated
2026-08-26

Who should care

Administrators of WordPress sites using the Simply Schedule Appointments plugin should verify and restrict access to user records in the plugin's REST endpoints to prevent unauthorized disclosure of registered user information. Additionally, security teams and vulnerability management teams should review the plugin's configuration and user access controls to ensure that they are properly set up to prevent such disclosures.

Technical summary

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see, allowing low-privileged staff role users to disclose names and email addresses of arbitrary registered users. This issue arises from inadequate access controls in the plugin's REST endpoints. Administrators should verify and restrict access to user records in the plugin's REST endpoints to prevent unauthorized disclosure of registered user information. Security teams should review the plugin's configuration and user access controls.

Defensive priority

Verify and restrict access to user records in Simply Schedule Appointments plugin REST endpoints.

Recommended defensive actions

  • Verify and restrict access to user records in Simply Schedule Appointments plugin REST endpoints.
  • Review and update Simply Schedule Appointments plugin to version 1.6.12.17 or later.
  • Monitor user records and REST endpoint access for potential abuse.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was created based on information from the NVD and a source item. Further details are needed to fully assess the vulnerability. The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This could potentially allow low-privileged staff role users to disclose names and email addresses of arbitrary registered users. To verify, defenders should review user records and REST endpoint access.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16541 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16541

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16541 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16541

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.