WordPress Plugin Vulnerabilities
Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR
Description
The plugin does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mark Moore
Submitter
Mark Moore
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-08 (about 2 months ago)
Added
2026-07-01 (about 2 months ago)
Last Updated
2026-08-10 (about 1 month ago)