CVE-2026-14224
Received Received - Intake

Unauthorized Customer Data Update in Easy Appointments Plugin

Vulnerability report for CVE-2026-14224, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: WPScan

Description

The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easy_appointments easy_appointments to 3.12.26 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) flaw in the Easy Appointments WordPress plugin up to version 3.12.26. A subscriber-level user can exploit a shared nonce from their own appointment to modify another user's appointment data, including email and contact details. When an admin updates the victim's appointment status with notifications enabled, the message is sent to the attacker's email instead.

Detection Guidance

Check if the Easy Appointments plugin version 3.12.26 or earlier is installed on your WordPress site. Log in as a subscriber and attempt to modify another user's appointment data using the shared nonce from your own appointment edit form. Monitor email notifications for unexpected redirections to attacker-controlled addresses.

Impact Analysis

If you use the Easy Appointments plugin with a subscriber account, an attacker could change your appointment's contact details to their email. This could lead to you missing important notifications or having your data exposed. Administrators could unknowingly send sensitive information to attackers.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's privacy rules. If appointment notifications containing personal details are sent to attackers, it may constitute a data breach requiring notification under these regulations.

Mitigation Strategies

Disable the Easy Appointments plugin until a patch is released. Restrict subscriber-level users from accessing sensitive appointment data. Review recent appointment notifications for unauthorized changes. Consider upgrading WordPress core and other plugins to minimize attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14224. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart