PatchSiren

Easy Appointments CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Easy Appointments CVE published 2026-09-08

CVE-2026-81798

CVE-2026-81798 is a Cross-site Scripting vulnerability in Easy Appointments, affecting versions from n/a through 4.0.2.1. Defenders should assess exposure, prioritize remediation, and verify inventory for potential impact. This DOM-Based XSS vulnerability allows for Cross-site Scripting attacks. The CVE record and NVD entry provide limited information on the vulnerability. Further verification is required [truncated]

LOW Easy Appointments CVE published 2026-08-06

CVE-2026-14225

The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes. This vulnerability has a CVSS score of 2.7 and LOW severity, indicating a [truncated]

MEDIUM Easy Appointments CVE published 2026-07-30

CVE-2026-14226

The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds. This allows users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses. The vulnerability is restricted to authenticated users wit [truncated]

MEDIUM Easy Appointments CVE published 2026-07-30

CVE-2026-14223

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. This vulnerability has a CVSS score of 4.3, indicating a medium severity. Users of the Easy Appointments WordPress plugin, particularly those with subscriber- [truncated]

LOW Easy Appointments CVE published 2026-07-30

CVE-2026-14222

The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. This vulnerability has a CVSS score of 3.8 and a CVSS severity of LOW. Affected users should verify the version of the plugin and update to 3.12.28 or [truncated]

MEDIUM Easy Appointments CVE published 2026-07-29

CVE-2026-14224

The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (ema [truncated]

HIGH Easy Appointments CVE published 2026-06-15

CVE-2026-39513

CVE-2026-39513 is a HIGH severity vulnerability (CVSS Score: 7.5) in Easy Appointments plugin versions <= 3.12.21. The vulnerability is caused by unauthenticated broken access control. The CVE was published on 2026-06-15T21:16:45.970Z and last modified on 2026-06-15T21:24:32.790Z.