Appointment Management Flaw in Easy Appointments Plugin for WordPress
CVE-2026-14221
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 30 July 2026
Badges
What is CVE-2026-14221?
The Easy Appointments plugin for WordPress fails to implement adequate capability checks in its appointment management processes. This oversight allows authenticated users with contributor-level access to bypass proper authorization and manipulate appointment details, including reading, creating, modifying, and deleting customer bookings. The reliance on a nonce alone, which any authenticated user can obtain, exposes sensitive customer information and compromises the integrity of the appointment management system.
Affected Version(s)
Easy Appointments 0 <= 3.12.26
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved