Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14222 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 3.8 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. | ||||
| CVE-2026-14221 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 3.8 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings. | ||||
| CVE-2026-14188 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 2.7 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | ||||
Page 1 of 1.