CVE-2026-9232
Received Received - Intake

Sensitive Information Exposure in Easy Appointments WordPress Plugin

Vulnerability report for CVE-2026-9232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: Wordfence

Description

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easy_appointments easy_appointments to 3.12.27 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Easy Appointments WordPress plugin allows authenticated users with contributor-level access or higher to access sensitive customer data from the ea_customers table. This includes personally identifiable information like names, email addresses, phone numbers, birth dates, and physical addresses.

Detection Guidance

To detect this vulnerability, check WordPress sites using the Easy Appointments plugin versions up to 3.12.27. Look for unauthorized access to the ea_customers table or unusual queries targeting customer data. Review server logs for suspicious AJAX requests to handle_customers_ajax.

Impact Analysis

If you use this plugin, attackers could steal customer data, leading to privacy breaches, identity theft, or reputational damage. Businesses may face legal consequences or loss of customer trust.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and HIPAA if health-related appointment data is exposed. Organizations could face fines or penalties for non-compliance.

Mitigation Strategies

Immediately update the Easy Appointments plugin to the latest version beyond 3.12.27. If an update is unavailable, consider disabling the plugin temporarily. Restrict contributor-level and higher access to sensitive data. Review and remove any exposed customer data from the ea_customers table.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart