CVE-2026-14221
Received Received - Intake

Easy Appointments WordPress Plugin Authentication Bypass

Vulnerability report for CVE-2026-14221, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
easy_appointments easy_appointments 3.12.26
easy_appointments easy_appointments to 3.12.26 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Easy Appointments WordPress plugin up to version 3.12.26 lacks proper authorization checks in appointment-management actions. It relies only on a nonce for security, which any authenticated user can obtain. This allows users with Contributor-level access to read all customers' appointment details, including sensitive PII, and to create, modify, or delete bookings.

Detection Guidance

Check if the Easy Appointments plugin version is 3.12.26 or lower. Inspect WordPress user roles with Contributor access for unusual appointment modifications or deletions. Review server logs for unauthorized API calls to appointment endpoints.

Impact Analysis

An attacker with Contributor access could steal sensitive customer data like names, emails, phone numbers, prices, and appointment dates. They could also manipulate or delete bookings, disrupting services and potentially causing financial or reputational harm.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of personally identifiable information (PII), violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties and compliance failures.

Mitigation Strategies

Update the Easy Appointments plugin to the latest version. Restrict Contributor role permissions to prevent access to appointment management actions. Monitor for unauthorized changes to appointments and sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14221. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart