What is CVE-2026-16541?
A vulnerability in the Simply Schedule Appointments WordPress plugin allows low-privileged users to view names and email addresses of arbitrary registered users via REST endpoints. Versions before 1.6.12.17 are affected, and administrators should update immediately.
Azərbaycanca: Simply Schedule Appointments WordPress plaginində aşkar edilmiş zəiflik aşağı səlahiyyətli istifadəçilərə REST API vasitəsilə ixtiyari qeydiyyatlı istifadəçilərin ad və email ünvanlarını görməyə imkan verir. Plaginin 1.6.12.17-dən əvvəlki versiyaları təsirlənir, inzibatçılar dərhal yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Who can exploit the CVE-2026-16541 vulnerability in the Simply Schedule Appointments plugin?
Low-privileged users can exploit the vulnerability to view names and email addresses of arbitrary registered users via REST endpoints.
What action is required to mitigate CVE-2026-16541?
The vulnerability affects versions before 1.6.12.17 of the Simply Schedule Appointments plugin, so administrators should update immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.