SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14226

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Easy Appointments WordPress plugin versions up to 3.12.26 are vulnerable due to insufficient access controls on appointment-listing REST endpoints, allowing authenticated users with subscriber-level access to view sensitive booking information, including customer names and schedules. This could lead to unauthorized data exposure, compromising user privacy and potentially impacting site integrity. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of data leaks.

CVE
CVE-2026-14226
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.