Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14.
Published: 2025-11-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of script‑related HTML tags, allowing a user to inject JavaScript code into pages rendered by the Easy Appointments plugin. This basic XSS flaw could be used to perform session hijacking, defacement, or phishing attacks against site visitors. The impact remains within the web interface of the plugin and does not provide direct remote code execution on the server, but any successful payload execution grants the attacker what the user can do in the compromised browser context.

Affected Systems

WordPress Easy Appointments plugin versions up to and including 3.12.14 are affected. The vulnerability exists in all releases prior to 3.12.15, so any WordPress site running the plugin on those versions is at risk. No other WordPress plugins or core components are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. Because the flaw is an XSS, an attacker typically needs a user to visit a page that incorporates the injected content, which may limit amateur attacker feasibility. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on April 30, 2026 at 05:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Appointments to version 3.12.15 or later
  • If an immediate upgrade is not possible, remove or delete the Easy Appointments plugin from the site
  • Implement a web application firewall or content security policy to block or sanitize executable script input

Generated by OpenCVE AI on April 30, 2026 at 05:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Tue, 11 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress
Vendors & Products Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14.
Title WordPress Easy Appointments plugin <= 3.12.14 - Content Injection vulnerability
Weaknesses CWE-80
References

Subscriptions

Easy-appointments Easy Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:03.285Z

Reserved: 2025-06-04T15:44:03.662Z

Link: CVE-2025-49398

cve-icon Vulnrichment

Updated: 2025-11-10T19:34:04.779Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:15:53.890

Modified: 2026-04-27T20:16:15.283

Link: CVE-2025-49398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:30:06Z

Weaknesses