CVE-2026-14221: Easy Appointments <= 4.0 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14221?
CVE-2026-14221 has a low severity rating of 3.8 according to CVSS 3.1.
How do I fix CVE-2026-14221?
To fix CVE-2026-14221, update the Easy Appointments plugin to a version greater than 3.12.26.
What type of data is at risk in CVE-2026-14221?
CVE-2026-14221 allows contributor-level users to read and modify customers' appointment details.
Who is affected by CVE-2026-14221?
Users with contributor-level access to the Easy Appointments plugin are affected by CVE-2026-14221.
What is the main issue in CVE-2026-14221?
CVE-2026-14221's main issue is the lack of authorization checks in the appointment-management actions of the Easy Appointments plugin.