PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9232 easyappointments CVE debrief

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.

Vendor
easyappointments
Product
Easy Appointments
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-19
Original CVE updated
2026-09-21
Advisory published
2026-09-19
Advisory updated
2026-09-21

Who should care

Defenders responsible for WordPress installations with the Easy Appointments plugin should assess exposure and implement compensating controls to protect customer data. This includes administrators, security teams, and IT personnel.

Why it matters

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure, allowing authenticated attackers to extract customer data. Defenders should prioritize verifying exposure and implementing compensating controls to protect customer data.

  • Authenticated attackers with contributor-level access and above can extract sensitive customer information
  • Customer data, including personally identifiable information, is at risk of exposure
  • Defenders must verify exposure and implement compensating controls to protect customer data
  • Remediation priority is high due to the potential for sensitive information exposure

Technical summary

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure due to an issue in the handle_customers_ajax function. This allows authenticated attackers with contributor-level access and above to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses. The vulnerability has a CVSS score of 6.5 and is considered MEDIUM severity. Defenders should prioritize verifying exposure and implementing compensating controls to protect customer

Defensive priority

Defenders should prioritize verifying exposure and implementing compensating controls to protect customer data.

Recommended defensive actions

  • Verify the version of the Easy Appointments plugin and update to a patched version if necessary
  • Restrict access to the handle_customers_ajax endpoint to prevent unauthorized access
  • Implement monitoring to detect potential exploitation attempts
  • Review and update contributor-level access and above to ensure proper authorization
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure due to an issue in the handle_customers_ajax function. This allows authenticated attackers with contributor-level access and above to extract the full customer dataset from the ea_customers table. Evidence is limited to public CVE and NVD information. Defenders should verify exposure and implement compensating controls to protect customer

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9232 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9232

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9232 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9232

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.