WordPress · Simply Schedule Appointments · CVE-2026-16540
**Name of the Vulnerable Software and Affected Versions**
Simply Schedule Appointments versions prior to 1.6.12.6
**Description**
An issue exists where a bulk appointment operation is not correctly restricted to the requester's own records. This allows unauthenticated users to retrieve personal data from all appointments across the site via the `/purge` endpoint. Additionally, in premium editions, this flaw enables the permanent deletion of these records.
**Recommendations**
Update Simply Schedule Appointments to version 1.6.12.6 or later.
Restrict access to the `/purge` endpoint as a temporary mitigation measure.