Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Easy Appointments — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Easy Appointments, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses associated with the Easy Appointments web-based appointment scheduling product, focusing on common vulnerability classes and specific tags relevant to its architecture. It compiles a comprehensive collection of reported flaws, including SQL injection, cross-site scripting, and authentication bypass issues that have been disclosed through vendor advisories, third-party security researchers, and public databases over the last several years. By organizing these findings into a single accessible location, the resource enables security professionals and administrators to track a vendor's advisory history and understand the evolving threat landscape surrounding this popular plugin. Users can also look up the specific product's vulnerability history to assess risk exposure and prioritize remediation efforts based on severity and exploit availability. The data is curated to help teams understand a weakness class within the context of this specific technology stack, providing actionable insights for patch management and security hardening. This aggregation serves as a central reference point for evaluating the security posture of Easy Appointments installations, highlighting recurring patterns in misconfigurations or code flaws. It supports informed decision-making by presenting historical trends and current known issues without overwhelming the user with redundant or unverified reports. The content is strictly informational, aiming to clarify the nature and impact of discovered defects while encouraging proactive security measures.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-14225 Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass 2.7 Low2026-08-06
CVE-2026-14222 Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Authorization --2026-07-30
CVE-2026-14226 Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing --2026-07-30
CVE-2026-14223 Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR --2026-07-30
CVE-2026-14188 Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure --2026-07-30
CVE-2026-14221 Easy Appointments <= 4.0 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization --2026-07-30
CVE-2026-14224 Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR --2026-07-29
CVE-2026-8789 Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion CWE-863 8.1 High2026-07-24
CVE-2026-61946 WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium2026-07-23
CVE-2026-11992 Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation CWE-862 4.3 Medium2026-07-10
CVE-2026-39513 WordPress Easy Appointments plugin <= 3.12.21 - Broken Access Control vulnerability CWE-862 7.5 High2026-06-15
CVE-2026-2262 Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API CWE-200 7.5 High2026-04-17
CVE-2025-49398 WordPress Easy Appointments plugin <= 3.12.14 - Content Injection vulnerability CWE-80 6.5 Medium2025-11-06
CVE-2023-30748 WordPress Easy Appointments plugin <= 3.10.7 - Auth. Stored Cross-Site Scripting (XSS) vulnerability CWE-79 4.3 Medium2024-12-09
CVE-2024-2844 Easy Appointments <= 3.11.18 - Insufficient Authorization CWE-862 4.3 Medium2024-03-29
CVE-2024-2842 Easy Appointments <= 3.11.18 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-29
CVE-2022-36424 WordPress Easy Appointments Plugin <= 3.11.9 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-07-17
CVE-2022-4668 Easy Appointments < 3.11.2 - Contributor+ Stored XSS in Shortcode 5.4 -2023-01-23

All 18 known CVE vulnerabilities affecting Easy Appointments with full Chinese analysis, references, and POCs where available.