Description
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.
Published: 2026-09-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Personal Information Exposure through missing authorization
Action: Immediate Patch
AI Analysis

Impact

The Easy Appointments plugin allows an authenticated user with contributor or higher privileges to call the ea_get_customers_ajax action, which returns the complete contents of the ea_customers table. Because the code performs no authorization check (CWE‑862), an attacker can obtain personally identifiable information such as names, email addresses, phone numbers, dates of birth, and mail addresses. The vulnerability does not provide remote code execution or denial of service, but it does lead to a serious privacy breach of customer data.

Affected Systems

WordPress sites running the Easy Appointments plugin with a version up to and including 3.12.27 are vulnerable. The issue affects the "easyappointments" plugin and all users who execute the ajax.php endpoint for customer retrieval. No specific operating system or WordPress core version is mentioned in the CNA data.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate confidentiality impact, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread exploitation has been reported. Successful exploitation requires an authenticated account with contributor or higher privileges and the ability to send a request to the ea_get_customers_ajax endpoint, a path that can be performed via normal site traffic once the user is logged in. The attack can be conducted remotely by any user who has received contributor rights.

Generated by OpenCVE AI on September 19, 2026 at 23:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Easy Appointments to a version newer than 3.12.27 where the missing authorization check has been added.
  • Limit WordPress contributor or higher roles to users who truly need them, removing unnecessary privileges.
  • Audit the site’s user accounts for appropriate role assignments and plan to reduce the number of users with contributor or higher access.

Generated by OpenCVE AI on September 19, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Easyappointments
Easyappointments easy!appointments
Wordpress
Wordpress wordpress
Vendors & Products Easyappointments
Easyappointments easy!appointments
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.
Title Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Easyappointments Easy!appointments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:23.219Z

Reserved: 2026-05-21T18:37:43.510Z

Link: CVE-2026-9232

cve-icon Vulnrichment

Updated: 2026-09-19T13:52:56.363Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:55.053

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses