Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Mon, 03 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nsqua
Nsqua simply Schedule Appointments Wordpress Wordpress wordpress |
|
| Vendors & Products |
Nsqua
Nsqua simply Schedule Appointments Wordpress Wordpress wordpress |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site. | |
| Title | Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-03T17:00:35.825Z
Reserved: 2026-07-09T12:55:11.383Z
Link: CVE-2026-15254
Updated: 2026-08-03T17:00:31.467Z
Status : Received
Published: 2026-08-03T07:16:39.987
Modified: 2026-08-03T17:16:30.253
Link: CVE-2026-15254
No data.
OpenCVE Enrichment
Updated: 2026-08-04T21:45:04Z