๐Ÿ” CVE Alert

CVE-2026-14224

UNKNOWN 0.0

Easy Appointments <= 3.12.26 - Subscriber+ Cross-User Appointment Data Modification via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.

Vendor unknown
Product easy appointments
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown easy appointments

Be the first to know when new unknown vulnerabilities affecting unknown easy appointments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Easy Appointments
0 โ‰ค 3.12.26

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c39226d5-1b6f-4f08-903c-7ecc67d17eb0/

Credits

Duy Tran WPScan