SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14223

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Easy Appointments plugin for WordPress versions up to 3.12.26 is vulnerable due to insufficient verification of ownership when accessing stored customer details, enabling users with subscriber-level access to retrieve sensitive personal information of any customer by manipulating identifiers. This vulnerability poses a medium risk, as it can lead to unauthorized exposure of personal data. WordPress site administrators using this plugin should prioritize applying updates or implementing mitigations to protect user privacy.

CVE
CVE-2026-14223
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.