Impact
The Easy Appointments plugin allows an authenticated user with contributor or higher privileges to call the ea_get_customers_ajax action, which returns the complete contents of the ea_customers table. Because the code performs no authorization check (CWE‑862), an attacker can obtain personally identifiable information such as names, email addresses, phone numbers, dates of birth, and mail addresses. The vulnerability does not provide remote code execution or denial of service, but it does lead to a serious privacy breach of customer data.
Affected Systems
WordPress sites running the Easy Appointments plugin with a version up to and including 3.12.27 are vulnerable. The issue affects the "easyappointments" plugin and all users who execute the ajax.php endpoint for customer retrieval. No specific operating system or WordPress core version is mentioned in the CNA data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate confidentiality impact, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread exploitation has been reported. Successful exploitation requires an authenticated account with contributor or higher privileges and the ability to send a request to the ea_get_customers_ajax endpoint, a path that can be performed via normal site traffic once the user is logged in. The attack can be conducted remotely by any user who has received contributor rights.
OpenCVE Enrichment