CVE-2026-16540: Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress plugin: Simply Schedule Appointmentsto a version that resolves this vulnerability.Fixed in 1.6.12.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16540?
CVE-2026-16540 has a risk rating of 80, indicating a high severity vulnerability.
How do I fix CVE-2026-16540?
To fix CVE-2026-16540, update the Simply Schedule Appointments plugin to version 1.6.12.6 or later.
What kind of data is affected by CVE-2026-16540?
CVE-2026-16540 allows unauthenticated users to access personal appointment data across the site.
Can CVE-2026-16540 allow unauthorized deletion of data?
Yes, CVE-2026-16540 can allow unauthorized users to permanently delete appointment records, especially in premium editions.
What plugin is associated with CVE-2026-16540?
CVE-2026-16540 is associated with the Simply Schedule Appointments WordPress plugin.