Vulnerabilities and security researches foreasy-appointments easy-appointments
Direction: descendingNov 11, 2025
Easy Appointments # CVE-2025-49398
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 06, 2025
- Research Description
- Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14.
- Affected versions
-
max 3.12.14.
- Status
-
vulnerable
Jun 10, 2024
Easy Appointments # CVE-2023-30748
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 09, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy Appointments allows Stored XSS.This issue affects Easy Appointments: from n/a through 3.10.7.
- Affected versions
-
max 3.11.1.
- Status
-
vulnerable
Jun 07, 2024
Easy Appointments # CVE-2022-4668
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 23, 2023
- Research Description
- The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
- Affected versions
-
max 3.11.2.
- Status
-
vulnerable
Easy Appointments # CVE-2022-36424
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 17, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions.
- Affected versions
-
max 3.11.10.
- Status
-
vulnerable
Easy Appointments # CVE-2024-2842
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 29, 2024
- Research Description
- The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calendar' shortcode in all versions up to, and including, 3.11.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 3.11.19.
- Status
-
vulnerable
Easy Appointments # CVE-2024-2844
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 29, 2024
- Research Description
- The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to cancel other users orders.
- Affected versions
-
max 3.11.19.
- Status
-
vulnerable
Easy Appointments # CVE-2017-15812
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 23, 2017
- Research Description
- The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.
- Affected versions
-
max 1.12.0.
- Status
-
vulnerable