What is CVE-2026-16540?
The CVE-2026-16540 vulnerability exists in the Simply Schedule Appointments WordPress plugin versions prior to 1.6.12.6. It allows unauthenticated attackers to access personal data of all appointments and, in premium editions, permanently delete them due to missing restrictions in bulk operations.
Azərbaycanca: CVE-2026-16540 zəifliyi Simply Schedule Appointments plugin-inin 1.6.12.6 versiyasından əvvəlki versiyalarında aşkarlanıb. Bu boşluq autentifikasiya olunmamış istifadəçilərə saytdakı bütün görüşlərin şəxsi məlumatlarını oxumağa və premium versiyalarda onları silməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-16540?
The CVE-2026-16540 vulnerability affects the Simply Schedule Appointments plugin.
Which versions of the Simply Schedule Appointments plugin are affected by CVE-2026-16540?
Versions prior to 1.6.12.6 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.