Impact
The Easy Appointments WordPress plugin before version 3.12.28 fails to verify ownership or capability when returning stored customer details, allowing any authenticated subscriber to iterate arbitrary identifiers and retrieve any customer's personal information. This direct object reference flaw (CWE‑639) results in PII disclosure but no code execution or denial of service is described.
Affected Systems
WordPress sites using the Easy Appointments plugin version 3.12.26 or older are impacted. All installations that have not applied a newer release that contains the fix are vulnerable. No evidence suggests earlier releases contain a remediation.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% points to a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers must possess a valid subscriber account and can gain the data by iterating through customer identifiers via the plugin’s data retrieval endpoint; successful exploitation results only in privacy leakage of the targeted customer’s PII.
OpenCVE Enrichment