Loading market data...
← Back to CVE feed

CVE-2026-16540

UNKNOWN View on NVD ↗

Description

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.

Published: Aug 02, 2026 06:16 UTC Modified: Aug 02, 2026 06:16 UTC