THREAT OPS › Threat News › [NVD] CVE-2026-14226 (MEDIUM 4.3) — The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookin
[NVD] CVE-2026-14226 (MEDIUM 4.3) — The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookin
CVE-2026-14226 CVSS: 4.3 MEDIUM Published: 2026-07-30T06:25:00.117
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules,
Indicators of compromise
- CVE-2026-14226cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14226