Description
Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Easy!Appointments WordPress plugin permits a Cross‑Site Request Forgery (CSRF) attack, enabling an unauthenticated or low‑privilege attacker to change the plugin's configuration settings. The flaw is discovered in all releases up to 1.4.2 and is characterized by a missing or improper CSRF token check when processing settings updates, as described in the CVE description. This weakness corresponds to CWE‑352, a classic CSRF scenario. The impact is limited to the scope of the affected plugin's settings and does not provide direct host or database access, but the ability to alter booking rules, email templates, or other operational parameters could be leveraged to cause denial of service, unauthorized scheduling, or phishing attempts.

Affected Systems

The affected product is the Easy!Appointments WordPress plugin developed by alextselegidis. All plugin versions through 1.4.2 are vulnerable. No additional vendor or system details are specified beyond the plugin itself.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate risk, with the attack requiring the victim to visit a crafted URL while authenticated or to exploit a cross‑site request. The EPSS score of less than 1% suggests the probability of exploitation is very low, and the vulnerability is not listed in CISA's KEV catalog. In practice, an attacker would need to lure a site administrator or moderator to click a malicious link or embed a malicious form and rely on the user having editing rights. Because this is a CSRF flaw, no remote code execution or privilege escalation outside the WordPress installation is provided by the flaw itself.

Generated by OpenCVE AI on May 1, 2026 at 11:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy!Appointments to the latest available version that addresses the CSRF issue; if version 1.4.2 is the last closed release, seek an updated patch from the plugin author or community repository.
  • Disable or remove access to the plugin’s settings page for users without elevated admin privileges by adjusting the WordPress role capabilities (e.g., remove 'edit_easyappointments_options' capability from non‑administrator roles).
  • Implement or enable a site‑wide CSRF protection plugin that adds tokens to all state‑changing forms and validates them before processing, providing an extra layer of defense against similar attacks.

Generated by OpenCVE AI on May 1, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9199 Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments allows Cross Site Request Forgery. This issue affects Easy!Appointments: from n/a through 1.4.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments allows Cross Site Request Forgery. This issue affects Easy!Appointments: from n/a through 1.4.2. Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 08 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Easyappointments
Easyappointments easy\!appointments
CPEs cpe:2.3:a:easyappointments:easy\!appointments:*:*:*:*:*:wordpress:*:*
Vendors & Products Easyappointments
Easyappointments easy\!appointments

Tue, 01 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments allows Cross Site Request Forgery. This issue affects Easy!Appointments: from n/a through 1.4.2.
Title WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Easyappointments Easy\!appointments
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:13.952Z

Reserved: 2025-04-01T13:20:32.606Z

Link: CVE-2025-31828

cve-icon Vulnrichment

Updated: 2025-04-01T17:59:29.341Z

cve-icon NVD

Status : Modified

Published: 2025-04-01T15:16:22.887

Modified: 2026-04-23T15:28:22.347

Link: CVE-2025-31828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses