Junglewise Threat Intelligence

CVE-2026-14222: Easy Appointments WordPress plugin unauthorized connection deletion

CVE-2026-14222 · Severity: info · CVSS 3.8 · Published 2026-07-30

Technologies: Easy Appointments. Vendors: Unknown, Easy Appointments.

Executive brief

The Easy Appointments plugin for WordPress, which manages scheduling and bookings, contains a security flaw that allows low-privileged users to delete critical configuration data. An attacker with a contributor-level account could delete booking connections, effectively disabling the appointment system on the website. This could lead to operational disruptions and a loss of customer bookings.

Technical details

The Easy Appointments plugin for WordPress (up to version 3.12.26) is vulnerable to missing authorization and Cross-Site Request Forgery (CSRF) in its AJAX handling. Specifically, the 'ea_delete_multiple_connections' action fails to implement nonce verification or capability checks (such as manage_options). An authenticated attacker with at least Contributor-level privileges can trigger this action to delete all booking connections. Because nonces are missing, the action is also susceptible to CSRF attacks targeting logged-in users with sufficient privileges. As of the advisory date, no patch is available.

Affected products

  • Unknown Easy Appointments <= 3.12.26

Timeline

  • 2026-07-01: disclosed: Vulnerability reported to WPScan
  • 2026-07-30: advisory: CVE published to NVD

References

Related threats