Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS.

This issue affects Easy Appointments: from n/a through 4.0.2.1.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: DOM Based XSS that allows arbitrary script execution in the victim’s browser
Action: Patch Immediately
AI Analysis

Impact

The Easy Appointments plugin fails to neutralize user supplied data before rendering it in the browser, creating a DOM‑based Cross‑Site Scripting flaw. An attacker can embed malicious JavaScript via crafted input or URLs. When a victim views a page that includes affected plugin output, the injected script runs in the victim’s browser in the context of the site, enabling cookie theft, session hijacking, data exfiltration, or malicious redirects.

Affected Systems

Any WordPress site that has the Easy Appointments plugin version 4.0.2.1 or earlier is vulnerable. The flaw exists in every release from the earliest available plugin versions up through 4.0.2.1.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact on web‑interface confidentiality and integrity. EPSS is not available and the vulnerability is not listed in KEV, suggesting limited known exploitation. The attack can be carried out from a remote malicious link or crafted form input; the attacker does not need privileged access or RCE, but a victim must view the affected page for the payload to execute.

Generated by OpenCVE AI on September 8, 2026 at 08:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Easy Appointments WordPress plugin to the newest released version (at least 4.0.3) to eliminate the XSS flaw.
  • If an update is not yet available, completely disable or uninstall the plugin until a patch is released.
  • Configure a web‑application firewall or input‑validation rules to strip or block unsanitized scripts that could be injected through the plugin’s input fields.

Generated by OpenCVE AI on September 8, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress
Vendors & Products Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress

Tue, 08 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.
Title WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Easy-appointments Easy Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-08T10:34:56.879Z

Reserved: 2026-08-27T12:24:38.075Z

Link: CVE-2026-81798

cve-icon Vulnrichment

Updated: 2026-09-08T10:31:53.251Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T08:17:13.013

Modified: 2026-09-08T13:12:58.310

Link: CVE-2026-81798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T09:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')