CyberRota Analysis
AI-GeneratedThe Easy Appointments WordPress plugin versions up to 3.12.26 are vulnerable due to insufficient access controls on appointment-listing REST endpoints, allowing authenticated users with subscriber-level access to view sensitive booking information, including customer names and schedules. This could lead to unauthorized data exposure, compromising user privacy and potentially impacting site integrity. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of data leaks.
Original NVD Description
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.