CVE-2026-16540 is an improper access control vulnerability in the Simply Schedule Appointments WordPress plugin before version 1.6.12.6. The plugin fails to properly constrain a bulk appointment operation to records owned or authorized for the requester. As a result, unauthenticated users can invoke the affected functionality to access appointment data belonging to all users across the site. In premium editions, the same access control weakness also permits permanent deletion of appointment records. The issue affects confidentiality by exposing appointment-related personal data and affects integrity and availability by allowing unauthorized destructive actions against stored appointment information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit/advisory package for CVE-2026-16540 affecting the Simply Schedule Appointments WordPress plugin before 1.6.12.6. The repository contains 4 files: a README with the vulnerability write-up, a short disclosure/advisory markdown file, a .gitignore, and one executable Bash PoC at poc/poc.sh. The only code file is the Bash script, which is the practical exploit entry point. The exploit targets a broken access control issue in the plugin's REST API. According to the documentation, the endpoint /wp-json/ssa/v1/appointments/purge uses a permission check that accepts a token proving ownership of a single appointment, but the purge handler then applies deletion or retrieval logic across all appointments matching supplied conditions rather than scoping to the caller's own appointment. This is a wrong-resource authorization flaw (CWE-863). The PoC demonstrates an unauthenticated attack chain: it first requests /wp-json/ssa/v1/embed-inner to extract a public nonce, then submits a POST to /wp-json/ssa/v1/appointments to create a booking with attacker-controlled customer data. From the JSON response it extracts data.id and data.public_token using python3 one-liners. It then calls /wp-json/ssa/v1/appointments/purge with id, token, purge_past_appointments=true, and generate_backup=false. Success is inferred from an HTTP 200 response, after which the script reports that all past appointments were deleted. Primary exploit capability shown in code: unauthorized mass deletion of past appointments. Additional capability described in the README but not directly demonstrated in the script: disclosure of appointment data/PII for all matching appointments site-wide. The exploit is operational rather than a mere detection script because it performs the full booking-plus-purge sequence against a live target. It is not part of a larger exploitation framework.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.