THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14226 (MEDIUM 4.3) — The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookin

[NVD] CVE-2026-14226 (MEDIUM 4.3) — The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookin

mednvdPublished 2026-07-30

CVE-2026-14226 CVSS: 4.3 MEDIUM Published: 2026-07-30T06:25:00.117

The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14226