What is CVE-2026-15254?
The Simply Schedule Appointments WordPress plugin before version 1.6.12.11 lacks a capability check on an admin appointment-listing shortcode, allowing users with Contributor role and above to disclose all customers' appointment data. Updating to the latest version is strongly recommended.
Azərbaycanca: Simply Schedule Appointments WordPress plaqini 1.6.12.11 versiyasından əvvəlki versiyalarda idarə panelindəki görüş siyahısı shortcode üçün lazımi icazə yoxlaması aparmır. Bu, Contributor və daha yuxarı rol sahiblərinə bütün müştərilərin görüş məlumatlarını açıq şəkildə əldə etməyə imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin does CVE-2026-15254 affect and what user roles are impacted?
The vulnerability affects the Simply Schedule Appointments plugin. It allows users with Contributor role and above (e.g., Author, Editor) to disclose all customers' appointment data.
To what version should the Simply Schedule Appointments plugin be updated to fix CVE-2026-15254?
To fix the vulnerability, it is strongly recommended to update the Simply Schedule Appointments plugin to at least version 1.6.12.11.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.