CVE-2026-14222: Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Authorization
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Easy Appointmentsto a version that resolves this vulnerability.Fixed in 3.12.28
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14222?
CVE-2026-14222 has a low severity rating of 3.8 according to the CVSS v3.1.
What does CVE-2026-14222 affect?
CVE-2026-14222 affects the Easy Appointments WordPress plugin versions up to 3.12.26.
How do I fix CVE-2026-14222?
To fix CVE-2026-14222, update the Easy Appointments WordPress plugin to a version newer than 3.12.26.
What risk does CVE-2026-14222 pose?
CVE-2026-14222 allows users with contributor-level access to delete booking configuration, potentially disrupting the booking system.
Does CVE-2026-14222 allow unauthorized access?
While CVE-2026-14222 does not grant unauthorized access, it allows contributors to delete important booking settings without proper authorization.