CVE-2026-87965
Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments.
| Vendor | unknown |
| Product | easy appointments |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown easy appointments
Be the first to know when new unknown vulnerabilities affecting unknown easy appointments are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Easy Appointments
0 < 4.0.2.2
References
Credits
Morato Antoine WPScan