Sensitive Information Exposure in Easy Appointments Plugin for WordPress
CVE-2026-9232

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

What is CVE-2026-9232?

The Easy Appointments plugin for WordPress is susceptible to a vulnerability that allows authenticated users with contributor-level access and higher to exploit the handle_customers_ajax functionality. This flaw enables these users to access and retrieve the complete customer dataset from the ea_customers table, risking exposure of sensitive personally identifiable information (PII) such as names, email addresses, mobile numbers, dates of birth, and physical addresses. It is crucial for website administrators to review their plugin versions and implement necessary updates to safeguard customer privacy.

Affected Version(s)

Easy Appointments 0 <= 3.12.27

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryoma Nishioka
.