CyberRota Analysis
AI-GeneratedThe Easy Appointments WordPress plugin versions up to 3.12.26 are vulnerable due to a lack of capability and nonce checks in a connection-deletion action, which allows users with contributor-level access to delete booking configurations and disable the booking system. While the severity is rated low, this vulnerability could disrupt booking functionalities for sites relying on the plugin. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential disruptions.
Original NVD Description
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.