Authorization Flaw in Easy Appointments WordPress Plugin
CVE-2026-14224
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 29 July 2026
Badges
What is CVE-2026-14224?
The Easy Appointments WordPress plugin, up to version 3.12.26, contains a weakness in its customer-data update process. This vulnerability allows an authenticated user to exploit the nonce verification mechanism. By using a nonce from their own appointment edit form, a subscriber can overwrite the customer metadata—such as email, name, phone, and description—of another user's appointment. This issue can lead to unauthorized email notifications being sent to the attacker-controlled address, as the plugin treats the altered metadata as the appointment's contact information.
Affected Version(s)
Easy Appointments 0 <= 3.12.26
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.