CVE-2026-19406
Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
| Vendor | unknown |
| Product | easy appointments |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown easy appointments
Be the first to know when new unknown vulnerabilities affecting unknown easy appointments are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Easy Appointments
3.12.28 < 4.0.1
References
Credits
Shikhali Jamalzade WPScan