Back to overview

CVE-2026-14224

Description
The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.

Metadata

CVE ID
CVE-2026-14224
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-30 11:51 UTC
Published
2026-07-29 06:00 UTC
Last updated
2026-07-29 06:00 UTC
Vendor / Product
Unknown / Easy Appointments
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Easy Appointments 0 ≤ 3.12.26
Weakness (CWE)
CWESourceDescription
cna CWE-639 Authorization Bypass Through User-Controlled Key
Back to overview