CyberRota Analysis
AI-GeneratedThe Easy Appointments plugin for WordPress versions up to 3.12.26 is vulnerable due to insufficient verification of ownership when accessing stored customer details, enabling users with subscriber-level access to retrieve sensitive personal information of any customer by manipulating identifiers. This vulnerability poses a medium risk, as it can lead to unauthorized exposure of personal data. WordPress site administrators using this plugin should prioritize applying updates or implementing mitigations to protect user privacy.
Original NVD Description
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.