VYPR

Easy Appointments

by WordPress

Source repositories

CVEs (23)

  • CVE-2026-8789HigJul 24, 2026
    risk 0.00cvss 8.1epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it…

  • CVE-2026-61946MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

  • CVE-2026-11992MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

Page 2 of 2