CVE-2022-2373: Simply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address Disclosure
Published Aug 29, 2022
·Updated
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
Affected Software
1 affected component
Nsqua Simply Schedule Appointments Wordpress<1.5.7.7
Event History
Aug 29, 2022
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2373?
CVE-2022-2373 has a moderate severity rating due to the potential exposure of sensitive user information.
2
How do I fix CVE-2022-2373?
To fix CVE-2022-2373, update the Simply Schedule Appointments plugin to version 1.5.7.7 or later.
3
What are the impacts of CVE-2022-2373?
The impact of CVE-2022-2373 allows unauthenticated users to gain access to WordPress users' details, such as names and email addresses.
4
Which versions of the Simply Schedule Appointments plugin are affected by CVE-2022-2373?
CVE-2022-2373 affects all versions of the Simply Schedule Appointments plugin prior to 1.5.7.7.
5
Is authentication required to exploit CVE-2022-2373?
No, CVE-2022-2373 can be exploited by unauthenticated users without any authentication required.