The Easy Appointments plugin for WordPress has a Sensitive Information Exposure vulnerability in all versions up to, and including, 3.12.27. This vulnerability allows authenticated attackers with contributor-level access and above to extract the full customer dataset, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses. Defen [truncated]
The Easy Appointments plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 3.12.27. This allows authenticated attackers with author-level access and above to cancel all upcoming appointments site-wide by marking every future appointment as abandoned. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Users of the Easy Appointments plugin for W [truncated]