Description
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
Published: 2026-08-19
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Appointments WordPress plugin fails to restrict one of its REST endpoints that lists appointment records. Contributors – users with a contributor role – can therefore request the entire list of bookings and receive sensitive data such as customer names, schedules, and statuses. This constitutes a confidentiality breach described by CWE‑200 and allows a user with only contributor‑level authentication to access data they should not see.

Affected Systems

The vulnerability affects any WordPress site that has the Easy Appointments plugin installed in a version earlier than 4.0.1. All contributor users on such installations are at risk, regardless of how many bookings exist on the site.

Risk and Exploitability

The CVSS score of 2.7 indicates low severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by authenticating as a contributor and sending a request to the unsecured REST endpoint; no elevated privileges or additional access are required. The outcome is the disclosure of all appointment records on the affected site.

Generated by OpenCVE AI on August 20, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Appointments to version 4.0.1 or later, which adds proper per‑user restrictions to appointment listings.
  • Reconfigure WordPress to limit contributor access to REST endpoints that return booking data, ensuring only administrators can query the full appointment list.
  • Audit role‑based permissions and apply the principle of least privilege so that contributors cannot access sensitive booking information.

Generated by OpenCVE AI on August 20, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress
Vendors & Products Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
Title Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing
References

Subscriptions

Easy-appointments Easy Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T16:34:36.190Z

Reserved: 2026-08-10T08:25:42.561Z

Link: CVE-2026-19406

cve-icon Vulnrichment

Updated: 2026-08-19T15:57:20.511Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:39.580

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-19406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T13:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor