WordPress Plugin Vulnerabilities

Easy Appointments < 4.0.1 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization

Description

The plugin does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.

Proof of Concept

Affects Plugins

Fixed in 4.0.1

References

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
Youssef massoudi
Submitter
Youssef massoudi
Verified
Yes

Timeline

Publicly Published
2026-07-08 (about 2 months ago)
Added
2026-07-01 (about 2 months ago)
Last Updated
2026-08-20 (about 21 days ago)

Other