WordPress Plugin Vulnerabilities

Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR

Description

The plugin does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.

Proof of Concept

Affects Plugins

Fixed in 3.12.28

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Mark Moore
Submitter
Mark Moore
Verified
Yes

Timeline

Publicly Published
2026-07-08 (about 2 months ago)
Added
2026-07-01 (about 2 months ago)
Last Updated
2026-08-10 (about 1 month ago)

Other