CyberRota Analysis
AI-GeneratedThe Easy Appointments WordPress plugin, up to version 3.12.26, is vulnerable due to a lack of proper capability and nonce checks in its customer-listing handlers, enabling authenticated users with contributor-level access to access sensitive personal information of all stored customers. While the severity is classified as low, organizations using this plugin should prioritize remediation to protect customer data and maintain compliance with privacy regulations. WordPress site administrators and security teams should assess their installations and apply necessary updates or mitigations.
Original NVD Description
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.