CVE-2026-81798: WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 8, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS.
This issue affects Easy Appointments: from n/a through 4.0.2.1.
Affected Software
1 affected component
WordPress Easy Appointments plugin<=4.0.2.1
Event History
Sep 8, 2026
CVE Published
via MITRE·07:18 AM
Data Sourced
via MITRE·07:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vector is network-accessible and requires no privileges, but exploitation requires user interaction. The available data does not specify what interaction is required.
2
Which plugin versions are affected?
Easy Appointments versions through 4.0.2.1 are affected. The lower bound is unspecified in the available data.
3
What security impact could successful exploitation have?
The reported CVSS vector indicates low potential impact to confidentiality, integrity, and availability, with scope changed. The issue is classified as DOM-based cross-site scripting.