PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14223 Easy Appointments CVE debrief

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. This vulnerability has a CVSS score of 4.3, indicating a medium severity. Users of the Easy Appointments WordPress plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take necessary precautions to protect customer information. The CVE record was published on 2026-07-30T06:25:00.010Z and has not been modified since then. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later, restrict access to customer details to authorized personnel only, and monitor for suspicious activity related to customer information.

Vendor
Easy Appointments
Product
Easy Appointments WordPress plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-08-10
Advisory published
2026-07-30
Advisory updated
2026-08-10

Who should care

Users of the Easy Appointments WordPress plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take necessary precautions to protect customer information. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later, restrict access to customer details to authorized personnel only, and monitor for suspicious activity related to customer information. Security teams and vulnerability management teams should prioritize this vulnerability and ensure that affected systems are remediated.

Technical summary

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. The vulnerability has a CVSS score of 4.3, indicating a medium severity. Affected organizations should review and update the Easy Appointments WordPress plugin to version 3.12.28 or later.

Defensive priority

CVE-2026-14223 has a CVSS score of 4.3, indicating a medium severity vulnerability. Users with subscriber-level access can read any customer's personal information by iterating an identifier.

Recommended defensive actions

  • Review and update Easy Appointments WordPress plugin to version 3.12.28 or later
  • Restrict access to customer details to authorized personnel only
  • Monitor for suspicious activity related to customer information
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details. This allows users with subscriber-level access to read any customer's personal information by iterating an identifier. The vulnerability has a CVSS score of 4.3, indicating a medium severity. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14223 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14223

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14223 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14223

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.