Easyappointments
Easyappointments Easy Appointments: vulnerabilidades y CVE
Easyappointments Easy Appointments tiene 23 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses23
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9232 | Media (6.5) | 0.47% | — | 19 sept 2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers,… |
| CVE-2026-87966 | Media (5.3) | 0.30% | — | 18 sept 2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a… |
| CVE-2026-87965 | Media (4.8) | 0.27% | — | 18 sept 2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded… |
| CVE-2026-81798 | Alta (7.1) | 0.25% | — | 8 sept 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1. |
| CVE-2026-19406 | Baja (2.7) | 0.32% | — | 19 ago 2026 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read… |
| CVE-2026-14225 | Baja (2.7) | 0.32% | — | 6 ago 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while… |
| CVE-2026-14226 | Media (4.3) | 0.29% | — | 30 jul 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds,… |
| CVE-2026-14223 | Media (4.3) | 0.27% | — | 30 jul 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal… |
| CVE-2026-14222 | Baja (3.8) | 0.32% | — | 30 jul 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking… |
| CVE-2026-14221 | Baja (3.8) | 0.26% | — | 30 jul 2026 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with… |
| CVE-2026-14188 | Baja (2.7) | 0.32% | — | 30 jul 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read… |
| CVE-2026-14224 | Media (5.4) | 0.23% | — | 29 jul 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any… |
| CVE-2026-8789 | Alta (8.1) | 0.40% | — | 24 jul 2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all… |
| CVE-2026-61946 | Media (6.5) | 0.33% | — | 23 jul 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. |
| CVE-2026-52841 | Baja (3.1) | 0.21% | — | 14 jul 2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and… |
| CVE-2026-52840 | Baja (2.7) | 0.31% | — | 14 jul 2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call… |
| CVE-2026-52839 | Baja (3.3) | 0.23% | — | 14 jul 2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended… |
| CVE-2026-52838 | Baja (2.6) | 0.24% | — | 14 jul 2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the… |
| CVE-2026-52837 | Media (6.9) | 0.56% | — | 14 jul 2026 | Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds… |
| CVE-2026-11992 | Media (4.3) | 0.46% | — | 10 jul 2026 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an… |
| CVE-2026-39513 | Alta (7.5) | 0.39% | — | 15 jun 2026 | Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. |
| CVE-2026-2262 | Alta (7.5) | 2.4% | — | 18 abr 2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due… |
| CVE-2025-49398 | Media (6.5) | 0.24% | — | 6 nov 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.