SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19406

LOW · CVSS 2.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Easy Appointments plugin for WordPress prior to version 4.0.1 has a vulnerability that allows users with contributor-level access to access all appointment records through an unprotected REST endpoint. This exposure can lead to unauthorized disclosure of sensitive information, including customer names and schedules. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.

CVE
CVE-2026-19406
Severity
LOW
CVSS
2.7
EPSS
0.23%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.