CVE-2026-14223
Received Received - Intake

Information Disclosure in Easy Appointments WordPress Plugin

Vulnerability report for CVE-2026-14223, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easy_appointments easy_appointments to 3.12.26 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the Easy Appointments WordPress plugin up to version 3.12.26. It allows users with subscriber-level access to read other customers' personal information by exploiting missing ownership or capability checks when retrieving customer details.

Detection Guidance

Check if the Easy Appointments plugin version is 3.12.26 or lower. Look for unauthorized access to customer PII by monitoring requests to admin-ajax.php with subscriber-level credentials. Enable logging for the 'Customer Search' feature if it is active.

Impact Analysis

If you have a subscriber account on a vulnerable site, an attacker could access your personal data. If you run such a site, attackers could steal customer PII including foreign data if the Customer Search feature is enabled. The attack involves scraping a nonce and sending crafted requests to admin-ajax.php.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personally identifiable information. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A breach could lead to legal penalties and reputational damage.

Mitigation Strategies

Disable the 'Customer Search' feature in the plugin settings. Remove or restrict subscriber-level access if not required. Monitor network traffic for suspicious requests to admin-ajax.php. Consider temporarily disabling the plugin until an official patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart