PatchSiren cyber security CVE debrief
CVE-2026-14223 Easy Appointments CVE debrief
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. This vulnerability has a CVSS score of 4.3, indicating a medium severity. Users of the Easy Appointments WordPress plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take necessary precautions to protect customer information. The CVE record was published on 2026-07-30T06:25:00.010Z and has not been modified since then. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later, restrict access to customer details to authorized personnel only, and monitor for suspicious activity related to customer information.
- Vendor
- Easy Appointments
- Product
- Easy Appointments WordPress plugin
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-08-10
Who should care
Users of the Easy Appointments WordPress plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take necessary precautions to protect customer information. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later, restrict access to customer details to authorized personnel only, and monitor for suspicious activity related to customer information. Security teams and vulnerability management teams should prioritize this vulnerability and ensure that affected systems are remediated.
Technical summary
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. The vulnerability has a CVSS score of 4.3, indicating a medium severity. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later.
Defensive priority
CVE-2026-14223 has a CVSS score of 4.3, indicating a medium severity vulnerability. Users with subscriber-level access can read any customer's personal information by iterating an identifier.
Recommended defensive actions
- Review and update Easy Appointments WordPress plugin to version 3.12.28 or later
- Restrict access to customer details to authorized personnel only
- Monitor for suspicious activity related to customer information
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details. This allows users with subscriber-level access to read any customer's personal information by iterating an identifier. The vulnerability has a CVSS score of 4.3, indicating a medium severity. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Official resources
-
CVE-2026-14223 CVE record
CVE.org
-
CVE-2026-14223 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T06:25:00.010Z and has not been modified since then.