Appointment shortcode exposes every customer's booking record
Simply Schedule Appointments before 1.6.12.11 omits a capability check from an administrative appointment-listing shortcode and its per-user filter fails open for non-staff users. A Contributor-or-higher user can render the shortcode and disclose every customer's appointment record across the site, including names, email addresses, phone numbers and notes.
- Component
- Simply Schedule Appointments
- Plugin slug
simply-schedule-appointments- Affected
- < 1.6.12.11
- Safe version
1.6.12.11- Published
- Aug 03, 2026
This CVE was published Aug 03, 2026 and is one of 38 known issues for this plugin.
Update, patch or deactivate.
Update Simply Schedule Appointments to 1.6.12.11 or later. Review use of administrative appointment shortcodes by delegated authors and handle exposed customer information according to applicable privacy obligations.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N