Easy Appointments

WordPress plugin · easy-appointments · WordPress.org ↗
0
Critical
0
High
10
Known total
1
Unfixed
Running Easy Appointments on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 4.8
Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token
CVE.org
>=0, <4.0.2.2 v4.0.2.2 CVE-2026-87965 Sep 18, 2026
MEDIUM
CVSS 5.3
Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR
CVE.org
>=4.0, <4.0.2.2 v4.0.2.2 CVE-2026-87966 Sep 18, 2026
MEDIUM
CVSS 4.3
Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
CVE.org
>=0, <3.12.28 v3.12.28 CVE-2026-14226 Jul 30, 2026
MEDIUM
CVSS 4.3
Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR
CVE.org
>=0, <3.12.28 v3.12.28 CVE-2026-14223 Jul 30, 2026
MEDIUM
CVSS 5.4
Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR
CVE.org
>=0, <3.12.28 v3.12.28 CVE-2026-14224 Jul 29, 2026
LOW
CVSS 2.7
Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing
CVE.org
>=3.12.28, <4.0.1 v4.0.1 CVE-2026-19406 Aug 19, 2026
LOW
CVSS 2.7
Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass
CVE.org
>=0, <3.12.28 v3.12.28 CVE-2026-14225 Aug 6, 2026
LOW
CVSS 2.7
Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure
CVE.org
>=0, <3.12.28 v3.12.28 CVE-2026-14188 Jul 30, 2026
LOW
CVSS 3.8
Easy Appointments <= 4.0 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization
CVE.org
<=4.0 unfixed CVE-2026-14221 Jul 30, 2026
LOW
CVSS 3.8
Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Authorization
CVE.org
>=0, <3.12.28 v3.12.28 CVE-2026-14222 Jul 30, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.