CVE-2026-15254 PUBLISHED

Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode

Assigner: WPScan
Reserved: 09.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.

Product Status

Vendor Unknown
Product Simply Schedule Appointments
Versions Default: unaffected
  • affected from 0 to 1.6.12.11 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE