Security Advisory

CVE-2026-14226

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 06:00:06
Last updated 2026-07-30 18:57:04
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.