VYPR

Easy Appointments

by WordPress

Source repositories

CVEs (28)

  • CVE-2026-14222LowJul 30, 2026
    risk 0.25cvss 3.8epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.

  • CVE-2026-14221LowJul 30, 2026
    risk 0.25cvss 3.8epss 0.00

    The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment…

  • CVE-2026-19406LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names,…

  • CVE-2026-14225LowAug 6, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with…

  • CVE-2026-14188LowJul 30, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.

  • CVE-2026-8789HigJul 24, 2026
    risk 0.00cvss 8.1epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it…

  • CVE-2026-61946MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

  • CVE-2026-11992MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

Page 2 of 2