
CVE-2026-16541 The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is… https://www.cve.org/CVERecord?id=CVE-2026-16541
Post summary
The text announces CVE‑2026‑16541, revealing that older versions of the Simply Schedule Appointments WordPress plugin wrongly return all user records on certain REST endpoints, exposing potential data leakage.
