CVE-2026-16540: The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-16540
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16540 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Simply Schedule Appointments
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-13400: Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in a…nvd · 2026-07-27
- mediumCVE-2026-59523: Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-a…nvd · 2026-07-13
- mediumCVE-2026-57812: Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-a…nvd · 2026-07-13
- highCVE-2026-57317: Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 version…nvd · 2026-06-26
More from NVD Recent CVEs
- mediumCVE-2026-18573: A flaw was found in the keycloak-services component of Keycloak, which is used for managing au…2026-08-02
- mediumCVE-2026-18572: Keycloak provides authorization services that allow administrators to restrict access to resou…2026-08-02
- mediumCVE-2026-18571: A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permission…2026-08-02
- mediumCVE-2026-18570: A flaw was found in the full-scope-disabled client-policy executor within the keycloak-service…2026-08-02
- unknownCVE-2026-16292: The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validati…2026-08-02