CVE-2026-14188
Deferred Deferred - Pending Action

Exposed Customer Data in Easy Appointments WordPress Plugin

Vulnerability report for CVE-2026-14188, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-08-10

Assigner: WPScan

Description

The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-08-10
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
easy_appointments easy_appointments 3.12.26
easy_appointments easy_appointments to 3.12.26 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Easy Appointments WordPress plugin through version 3.12.26 has a vulnerability where it fails to verify user permissions or request authenticity for a specific customer-listing function. This allows users with contributor-level access to view all stored customer personal information without proper authorization.

Detection Guidance

Check if the Easy Appointments plugin version is 3.12.26 or lower. Log in as a contributor and attempt to access customer data via the vulnerable handler. Look for unusual requests to endpoints handling customer listings.

Impact Analysis

If you use this plugin with contributor accounts, unauthorized users could access sensitive customer data including personal information stored in the ea_customers table. This could lead to privacy breaches and misuse of customer data.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for protecting personal and health-related data. Unauthorized access to customer information could result in legal penalties, fines, and reputational damage due to non-compliance with data protection regulations.

Mitigation Strategies

Update the Easy Appointments plugin to the latest version beyond 3.12.26. Remove or restrict contributor-level access if not necessary. Monitor for unauthorized access to customer data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14188. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart