Executive brief
Easy Appointments is a WordPress plugin used to manage customer bookings and schedules. A security flaw allows users with low-level 'Contributor' accounts to access the full database of customer personal information, including names, emails, phone numbers, and addresses. This could lead to significant privacy breaches and the exposure of sensitive client data to unauthorized internal users.
Technical details
The vulnerability is a sensitive data disclosure issue within the 'ea_get_customers_ajax' handler in admin-ajax.php. The plugin fails to implement proper authorization (capability checks) or CSRF protection (nonces) on this specific AJAX action. An authenticated attacker with 'Contributor' level permissions (or any role possessing the 'edit_posts' capability) can send a POST request to the handler to retrieve JSON-formatted customer records. The exposed data includes full names, email addresses, mobile phone numbers, dates of birth, and physical addresses. As of the advisory date, no fix has been confirmed for version 3.12.26.
Affected products
- Unknown Easy Appointments <= 3.12.26
Timeline
- 2026-07-01: other: Vulnerability added to WPScan database
- 2026-07-08: disclosed: Public disclosure
- 2026-07-30: advisory: NVD publication date