Data Modification Vulnerability in Easy Appointments Plugin for WordPress
CVE-2026-8789
8.1HIGH
What is CVE-2026-8789?
The Easy Appointments plugin for WordPress contains a vulnerability that allows attackers to modify critical data due to inadequate capability checks and nonce verification. Specifically, the lack of these security measures on the ea_delete_multiple_connections AJAX action permits authenticated users with Contributor-level access or higher to delete entries in the wp_ea_connections database table. This exploitation compromises the functionality of the booking system, potentially disrupting operations for users relying on this plugin.
Affected Version(s)
Easy Appointments 0 <= 3.12.27