---
id: CVE-2026-16540
title: >-
  The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not
  correctly restrict a bulk appointment operation to the requester's own
  records, allowing unauthenticated users to retrieve the personal data of all
  appointments a…
summary: >-
  The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not
  correctly restrict a bulk appointment operation to the requester's own
  records, allowing unauthenticated users to retrieve the personal data of all
  appointments a…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16540'
references:
  - url: 'https://wpscan.com/vulnerability/c3829294-c388-4151-9e25-a3eac7b1f1c6/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
ingestedAt: '2026-08-02T13:18:29.676Z'
epss: 0.00406
epssPercentile: 0.32105
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/huseyn0vs/CVE-2026-16540-SimplyScheduleAppointments'
  checkedAt: '2026-09-25T08:20:51.274Z'
exploitAvailable: true
---

## Overview

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
