cleantalk
Vulnerabilities and Security Researches

Easy Appointments, CVE-2026-87966

CVE, Research URL

CVE-2026-87966

Application

Easy Appointments

Published on
Sep 18, 2026
Research Description
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.
Affected versions
Min 4.0, max 4.0.2.2.
Status
vulnerable