Junglewise Threat Intelligence

CVE-2026-39513: Easy Appointments WordPress plugin broken access control

CVE-2026-39513 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: Easy Appointments. Vendors: Easy Appointments.

Executive brief

Easy Appointments is a WordPress plugin used to manage bookings and scheduling. A security flaw allows unauthorized individuals to bypass access controls, potentially leading to the exposure of sensitive appointment data or customer information. This could result in privacy breaches and reputational damage for businesses relying on the plugin for client management.

Technical details

The Easy Appointments plugin for WordPress (versions up to and including 3.12.21) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw by sending crafted requests to the affected component, bypassing intended restrictions. This allows the attacker to perform actions or access data that should be restricted to higher-privileged users, specifically impacting confidentiality (CVSS C:H). The issue is resolved in version 3.12.22.

Affected products

  • Easy Appointments Easy Appointments <= 3.12.21

Timeline

  • 2026-02-17: other: Reported by researcher Martín Martín
  • 2026-04-13: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats