PatchSiren

Simply Schedule CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Simply Schedule CVE published 2026-08-15

CVE-2026-16541

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict user records returned by some REST endpoints to those the requester is entitled to see. This allows low-privileged staff role users to disclose names and email addresses of arbitrary registered users. The vulnerability affects WordPress sites using the Simply Schedule Appointments plugin. To verify, defenders should revie [truncated]

MEDIUM Simply Schedule CVE published 2026-08-03

CVE-2026-15254

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.

HIGH Simply Schedule CVE published 2026-08-02

CVE-2026-16540

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. This vulnerability allows unauthenticated access to sensitive appointment data and potential deletion [truncated]

MEDIUM Simply Schedule CVE published 2026-07-27

CVE-2026-13400

The Simply Schedule Appointments plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a [truncated]