{"api_version":"1","generated_at":"2026-08-16T10:23:47+00:00","cve":"CVE-2026-16541","urls":{"html":"https://cve.report/CVE-2026-16541","api":"https://cve.report/api/cve/CVE-2026-16541.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16541","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16541"},"summary":{"title":"Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints","description":"The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-15 06:17:08","updated_at":"2026-08-15 06:17:08"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/8172f778-5dc5-49e8-9967-81215ac187d7/","name":"https://wpscan.com/vulnerability/8172f778-5dc5-49e8-9967-81215ac187d7/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16541","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16541","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Simply Schedule Appointments","version":"affected 1.6.12.17 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Yaswanth Reddy Sunkara","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"16541","cve":"CVE-2026-16541","epss":"0.001390000","percentile":"0.037620000","score_date":"2026-08-15","updated_at":"2026-08-16 00:00:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Simply Schedule Appointments","vendor":"Unknown","versions":[{"lessThan":"1.6.12.17","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Yaswanth Reddy Sunkara"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-15T06:00:14.643Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/8172f778-5dc5-49e8-9967-81215ac187d7/"}],"source":{"discovery":"EXTERNAL"},"title":"Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-16541","datePublished":"2026-08-15T06:00:14.643Z","dateReserved":"2026-07-22T09:40:21.237Z","dateUpdated":"2026-08-15T06:00:14.643Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:17:08","lastModifiedDate":"2026-08-15 06:17:08","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16541","Ordinal":"1","Title":"Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Ema","CVE":"CVE-2026-16541","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16541","Ordinal":"1","NoteData":"The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.","Type":"Description","Title":"Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Ema"}]}}}