Executive brief
Easy Appointments is a WordPress plugin used to manage bookings and scheduling. A security flaw allows unauthorized individuals to bypass access controls, potentially leading to the exposure of sensitive appointment data or customer information. This could result in privacy breaches and reputational damage for businesses relying on the plugin for client management.
Technical details
The Easy Appointments plugin for WordPress (versions up to and including 3.12.21) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw by sending crafted requests to the affected component, bypassing intended restrictions. This allows the attacker to perform actions or access data that should be restricted to higher-privileged users, specifically impacting confidentiality (CVSS C:H). The issue is resolved in version 3.12.22.
Affected products
- Easy Appointments Easy Appointments <= 3.12.21
Timeline
- 2026-02-17: other: Reported by researcher Martín Martín
- 2026-04-13: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date