The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This allows low-privileged staff role users to disclose names and email addresses of arbitrary registered users. The vulnerability affects WordPress sites using the Simply Schedule Appointments plugin. To verify, defenders should revie [truncated]
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. This vulnerability allows unauthenticated access to sensitive appointment data and potential deletion [truncated]
The Simply Schedule Appointments plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a [truncated]