CyberRota Analysis
AI-GeneratedThe Simply Schedule Appointments plugin for WordPress versions prior to 1.6.12.11 is vulnerable due to inadequate capability checks on an administrative shortcode, allowing users with Contributor roles and higher to access sensitive customer appointment records site-wide. This exposure can lead to unauthorized disclosure of personal information, including names, email addresses, and phone numbers. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.