Feed/CVE-2026-14226
CVE-2026-14226MEDIUMCVSS 4.3

CVE-2026-14226

Published Jul 30, 2026·Updated Aug 10, 2026

NVD Description

The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free