PatchSiren cyber security CVE debrief
CVE-2026-9232 easyappointments CVE debrief
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.
- Vendor
- easyappointments
- Product
- Easy Appointments
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-19
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-19
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for WordPress installations with the Easy Appointments plugin should assess exposure and implement compensating controls to protect customer data. This includes administrators, security teams, and IT personnel.
Why it matters
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure, allowing authenticated attackers to extract customer data. Defenders should prioritize verifying exposure and implementing compensating controls to protect customer data.
- Authenticated attackers with contributor-level access and above can extract sensitive customer information
- Customer data, including personally identifiable information, is at risk of exposure
- Defenders must verify exposure and implement compensating controls to protect customer data
- Remediation priority is high due to the potential for sensitive information exposure
Technical summary
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure due to an issue in the handle_customers_ajax function. This allows authenticated attackers with contributor-level access and above to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses. The vulnerability has a CVSS score of 6.5 and is considered MEDIUM severity. Defenders should prioritize verifying exposure and implementing compensating controls to protect customer
Defensive priority
Defenders should prioritize verifying exposure and implementing compensating controls to protect customer data.
Recommended defensive actions
- Verify the version of the Easy Appointments plugin and update to a patched version if necessary
- Restrict access to the handle_customers_ajax endpoint to prevent unauthorized access
- Implement monitoring to detect potential exploitation attempts
- Review and update contributor-level access and above to ensure proper authorization
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure due to an issue in the handle_customers_ajax function. This allows authenticated attackers with contributor-level access and above to extract the full customer dataset from the ea_customers table. Evidence is limited to public CVE and NVD information. Defenders should verify exposure and implement compensating controls to protect customer
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9232 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9232
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9232 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9232
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/ajax.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3595856
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.