Description
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated appointment manipulation
Action: Patch Now
AI Analysis

Impact

The Easy Appointments WordPress plugin prior to version 4.0.2.2 fails to perform an ownership or authorization check on its appointment‑reservation endpoint. An attacker who can send an unauthenticated HTTP request can supply any appointment identifier and overwrite the corresponding appointment data. The flaw also permits the deletion of appointments through a follow‑on cleanup action. The weakness is an IDOR flaw, documented as CWE-639, and consequently allows an attacker to arbitrarily modify or delete appointments, which can lead to scheduling disruption and data loss.

Affected Systems

The vulnerable product is the Easy Appointments WordPress plugin, labeled generically as "Easy Appointments". Based on the description, it is inferred that all releases from version 4.0 up to 4.0.2.1 are affected; the issue is fixed in 4.0.2.2 and later.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating a moderate severity and a low exploitability reflected by an EPSS score of less than 1%. It is not listed in the CISA KEV catalog, suggesting no publicly available exploitation. Nevertheless, the flaw is exploitable by anyone with internet access to the vulnerable WordPress site, as it does not require authentication. The attack path involves submitting a crafted request to the appointment‑reservation endpoint with a chosen ID, enabling unauthorized appointment manipulation. While the probability of exploitation is currently low, the potential impact on business continuity and data integrity warrants prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 19:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Easy Appointments to version 4.0.2.2 or later.
  • If an immediate upgrade is infeasible, enforce authentication on all appointment reservation requests, for example by configuring the plugin or applying role‑based access control to restrict creation and modification to logged‑in users.
  • Consider disabling or removing Easy Appointments until a patch is applied, or block the appointment‑reservation endpoint with a web application firewall to prevent unauthenticated access.

Generated by OpenCVE AI on September 19, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress
Vendors & Products Easy-appointments
Easy-appointments easy Appointments
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.
Title Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR
References

Subscriptions

Easy-appointments Easy Appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:09:27.511Z

Reserved: 2026-09-09T17:46:45.657Z

Link: CVE-2026-87966

cve-icon Vulnrichment

Updated: 2026-09-18T11:01:44.986Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:40.950

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-87966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key