Executive brief
Simply Schedule Appointments is a WordPress plugin used by businesses to manage client bookings and scheduling. A security flaw in versions older than 1.6.11.2 allows unauthorized individuals to access sensitive information that should be private. This could lead to the exposure of customer data or internal system details, potentially facilitating further attacks on the website.
Technical details
The Simply Schedule Appointments plugin for WordPress is vulnerable to sensitive data exposure (CWE-201) in versions prior to 1.6.11.2. The vulnerability allows an unauthenticated remote attacker to access sensitive information due to improper data handling within the plugin's components. With a CVSS score of 7.5, the flaw is exploitable over the network without user interaction or administrative privileges. Attackers can leverage this exposure to gather information that may assist in further compromising the WordPress environment. Users are advised to update to version 1.6.11.2 or later to remediate the issue.
Affected products
- NSquared Simply Schedule Appointments < 1.6.11.2
Timeline
- 2026-03-07: other: Reported by Jakub Herman
- 2026-04-27: advisory: Patchstack advisory published
- 2026-04-27: patched: Patch released in version 1.6.11.2
- 2026-06-15: disclosed: CVE published to NVD