Easy Appointments WordPress plugin <= 3.12.21 contains a sensitive information exposure caused by an unauthenticated REST API endpoint /wp-json/wp/v2/eablocks/ea_appointments/ registered with permission_callback allowing unrestricted access, letting unauthenticated attackers extract sensitive customer appointment data.
id: CVE-2026-2262
info:
name: Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Informatio
...