SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14221

LOW · CVSS 3.8 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Easy Appointments plugin for WordPress versions up to 3.12.26 is vulnerable due to inadequate capability checks in its appointment-management functions, allowing authenticated users with contributor-level access to read, create, modify, and delete all customers' appointment details. This could lead to unauthorized access and manipulation of sensitive booking information. WordPress site administrators using this plugin should prioritize patching or updating to mitigate potential data exposure risks.

CVE
CVE-2026-14221
Severity
LOW
CVSS
3.8
EPSS
0.19%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.