SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14222

LOW · CVSS 3.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Easy Appointments WordPress plugin versions up to 3.12.26 are vulnerable due to a lack of capability and nonce checks in a connection-deletion action, which allows users with contributor-level access to delete booking configurations and disable the booking system. While the severity is rated low, this vulnerability could disrupt booking functionalities for sites relying on the plugin. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential disruptions.

CVE
CVE-2026-14222
Severity
LOW
CVSS
3.8
EPSS
0.24%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.