Unrated severityNVD Advisory· Published Sep 18, 2026
CVE-2026-87966
CVE-2026-87966
Description
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.0.2.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.