WordPress Simply Schedule Appointments plugin before 1.5.7.7 is susceptible to information disclosure. The plugin is missing authorization in a REST endpoint, which can allow an attacker to retrieve user details such as name and email address.
id: CVE-2022-2373
info:
name: WordPress Simply Schedule Appointments <1.5.7.7 - Information Discl
...