VYPR
Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026

Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization

CVE-2026-14222

Description

The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.