Junglewise Threat Intelligence

CVE-2026-61946: Easy Appointments IDOR in WordPress plugin

CVE-2026-61946 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Technologies: Easy Appointments. Vendors: Easy Appointments.

Executive brief

Easy Appointments is a WordPress plugin used to manage bookings and scheduling. A security flaw allows unauthenticated users to access or modify data they should not have permission to see by manipulating object identifiers. This could lead to unauthorized changes to appointments or interference with the booking database, potentially disrupting business operations and customer scheduling.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Easy Appointments plugin for WordPress through version 3.12.27. The flaw is categorized as CWE-639, where the application fails to properly validate authorization when a user-controlled key is used to access a database object. An unauthenticated remote attacker can exploit this by manipulating input parameters to bypass authorization checks. This may allow the attacker to interact with the database or modify records without valid credentials. The issue is resolved in version 3.12.28.

Affected products

  • Easy Appointments Easy Appointments <= 3.12.27

Timeline

  • 2026-04-03: other: Vulnerability reported by Daniel Wade
  • 2026-07-16: advisory: Patchstack published advisory details
  • 2026-07-23: disclosed: CVE published to NVD dataset

References

Related threats