Junglewise Threat Intelligence

CVE-2026-14224: Easy Appointments WordPress plugin IDOR in customer-data update

CVE-2026-14224 · Severity: info · CVSS 5.4 · Published 2026-07-29

Technologies: Easy Appointments. Vendors: Easy Appointments.

Executive brief

The Easy Appointments plugin for WordPress, which manages scheduling and customer bookings, contains a security flaw that allows one customer to modify the details of another customer's appointment. By exploiting this, an attacker can change the contact information (such as email and phone number) on a victim's booking. This could lead to the attacker receiving sensitive appointment notifications intended for the victim, potentially resulting in the exposure of private service details or unauthorized access to appointment-related communications.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the 'ea_update_customer_data' AJAX action of the Easy Appointments plugin through version 3.12.26. The plugin fails to perform an ownership check on the 'appointment_id' parameter during the update process, relying instead on a shared nonce that any authenticated user can generate via their own appointment edit form. A subscriber-level attacker can obtain a valid nonce from their own appointment and replay it against a victim's appointment ID to overwrite metadata including name, email, phone, and description. This allows for data manipulation and can lead to information disclosure if an administrator triggers a notification, as the system will send the victim's appointment details to the attacker-controlled email address.

Affected products

  • Easy Appointments Easy Appointments <= 3.12.26

Timeline

  • 2026-06-30: disclosed
  • 2026-07-29: advisory: NVD publication date

References

Related threats