Description
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
Published: 2026-07-30
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Appointments WordPress plugin before version 3.12.28 does not perform any capability or nonce check in one of its connection‑deletion actions, enabling users with contributor‑level access to delete the entire booking configuration and thus disable the booking system. This represents an authorization bypass (CWE‑284) that results in loss of service availability and loss of configuration data.

Affected Systems

WordPress sites that install Easy Appointments up to and including version 3.12.27. The plugin is distributed as a WordPress plugin under the Easy Appointments name, and no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 3.8 classifies this vulnerability as low severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not catalogued in the CISA KEV list. Attackers would need to obtain a contributor‑level login to a WordPress site that uses the affected plugin, and then trigger the connection‑deletion action. Because the flaw is limited to plugin file operations and does not provide remote code execution, the risk to confidentiality or integrity is minimal; the primary risk is to availability and configuration.

Generated by OpenCVE AI on August 10, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Easy Appointments to version 3.12.28 or later, which includes the necessary capability check for the deletion action.
  • If an update is not immediately possible, remove or restrict the delete capability from contributor roles in WordPress, ensuring that only users with appropriate administrative privileges can alter booking configurations.
  • Verify and monitor WordPress role assignments to prevent unintentional elevation of contributor-level users and audit deletion logs for unexpected booking configuration changes.

Generated by OpenCVE AI on August 10, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
Title Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Authorization

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress
Vendors & Products Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
Title Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization
References

Subscriptions

Easy-appointments Easy Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T12:33:34.970Z

Reserved: 2026-06-30T11:51:23.181Z

Link: CVE-2026-14222

cve-icon Vulnrichment

Updated: 2026-07-30T18:44:59.364Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:24:59.907

Modified: 2026-08-10T13:17:57.297

Link: CVE-2026-14222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T14:15:03Z

Weaknesses