Unrated severityNVD Advisory· Published Aug 19, 2026
CVE-2026-19406
CVE-2026-19406
Description
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.0.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.