WordPress Simply Schedule Appointments plugin before 1.5.7.7 is susceptible to information disclosure. The plugin is missing authorization in a REST endpoint, which can allow an attacker to retrieve user details such as name and email address.
View the template here CVE-2022-2373.yaml
References:
https://github.com/ARPSyndicate/cvemon