Description
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
Published: 2026-07-30
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Appointments WordPress plugin up to version 3.12.27 fails to perform a per‑request capability or nonce check on a customer‑listing handler, which permits authenticated users with contributor privileges to read the personal data of all stored customers. This omission represents a confidentiality breach (CWE‑200). No code execution or denial‑of‑service scenarios are described, and the impact is limited to data exposure rather than system compromise.

Affected Systems

WordPress sites that have the Easy Appointments plugin installed, any version 3.12.27 or earlier. The CNA vendor is listed simply as Easy Appointments, and no additional OEMs or hosting platforms are identified. Users of older releases should verify the installed version against their plugin inventory.

Risk and Exploitability

The CVSS base score of 2.7 indicates a low overall risk, largely because the vulnerability requires prior authentication and only affords read‑only access to customer data. The EPSS score, falling below 1 %, further suggests that real‑world exploitation is unlikely at this time. The vulnerability is not present in the CISA KEV catalog. Attackers would need to be authenticated with a contributor role, making internal privilege escalation the primary vector. Consequently, while the potential data exposure could be significant for a specific organization, the overall threat level remains modest.

Generated by OpenCVE AI on August 10, 2026 at 22:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Appointments to version 3.12.28 or later to restore proper nonce and capability checks.
  • If an upgrade is delayed, remove or constrain the contributor role from staff members who do not need access to customer listings; consider changing contributors to the ‘author’ role or revoking the plugin’s read‑customer capability.
  • Monitor user permission assignments and audit plugin configuration changes to ensure no revert to the vulnerable state occurs during maintenance or updates.

Generated by OpenCVE AI on August 10, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
Title Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress
Vendors & Products Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
Title Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure
References

Subscriptions

Easy-appointments Easy Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T12:42:33.639Z

Reserved: 2026-06-30T08:25:41.301Z

Link: CVE-2026-14188

cve-icon Vulnrichment

Updated: 2026-07-30T14:12:18.770Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:24:59.613

Modified: 2026-08-10T13:17:56.963

Link: CVE-2026-14188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T22:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor