SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14188

LOW · CVSS 2.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Easy Appointments WordPress plugin, up to version 3.12.26, is vulnerable due to a lack of proper capability and nonce checks in its customer-listing handlers, enabling authenticated users with contributor-level access to access sensitive personal information of all stored customers. While the severity is classified as low, organizations using this plugin should prioritize remediation to protect customer data and maintain compliance with privacy regulations. WordPress site administrators and security teams should assess their installations and apply necessary updates or mitigations.

CVE
CVE-2026-14188
Severity
LOW
CVSS
2.7
EPSS
0.23%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.