Authorization Flaw in Easy Appointments WordPress Plugin
CVE-2026-14224

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 July 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-14224?

The Easy Appointments WordPress plugin, up to version 3.12.26, contains a weakness in its customer-data update process. This vulnerability allows an authenticated user to exploit the nonce verification mechanism. By using a nonce from their own appointment edit form, a subscriber can overwrite the customer metadata—such as email, name, phone, and description—of another user's appointment. This issue can lead to unauthorized email notifications being sent to the attacker-controlled address, as the plugin treats the altered metadata as the appointment's contact information.

Affected Version(s)

Easy Appointments 0 <= 3.12.26

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Duy Tran
WPScan
.