PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14223 Easy Appointments CVE debrief

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. This vulnerability has a CVSS score of 4.3, indicating a medium severity. Users of the Easy Appointments WordPress plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take necessary precautions to protect customer information. The CVE record was published on 2026-07-30T06:25:00.010Z and has not been modified since then. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later, restrict access to customer details to authorized personnel only, and monitor for suspicious activity related to customer information.

Vendor
Easy Appointments
Product
Easy Appointments WordPress plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-08-10
Advisory published
2026-07-30
Advisory updated
2026-08-10

Who should care

Users of the Easy Appointments WordPress plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take necessary precautions to protect customer information. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later, restrict access to customer details to authorized personnel only, and monitor for suspicious activity related to customer information. Security teams and vulnerability management teams should prioritize this vulnerability and ensure that affected systems are remediated.

Technical summary

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. The vulnerability has a CVSS score of 4.3, indicating a medium severity. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later.

Defensive priority

CVE-2026-14223 has a CVSS score of 4.3, indicating a medium severity vulnerability. Users with subscriber-level access can read any customer's personal information by iterating an identifier.

Recommended defensive actions

  • Review and update Easy Appointments WordPress plugin to version 3.12.28 or later
  • Restrict access to customer details to authorized personnel only
  • Monitor for suspicious activity related to customer information
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details. This allows users with subscriber-level access to read any customer's personal information by iterating an identifier. The vulnerability has a CVSS score of 4.3, indicating a medium severity. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T06:25:00.010Z and has not been modified since then.