Sensitive Information Exposure in Easy Appointments Plugin for WordPress
CVE-2026-9232
6.5MEDIUM
What is CVE-2026-9232?
The Easy Appointments plugin for WordPress is susceptible to a vulnerability that allows authenticated users with contributor-level access and higher to exploit the handle_customers_ajax functionality. This flaw enables these users to access and retrieve the complete customer dataset from the ea_customers table, risking exposure of sensitive personally identifiable information (PII) such as names, email addresses, mobile numbers, dates of birth, and physical addresses. It is crucial for website administrators to review their plugin versions and implement necessary updates to safeguard customer privacy.
Affected Version(s)
Easy Appointments 0 <= 3.12.27