← Πίσω στην αναζήτηση CVE

CVE-2026-14224

Easy Appointments

Περιγραφή

The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment-s edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user-s appointment. Because the Easy Appointments WordPress plugin before 3.12.28 then treats that metadata as the appointment-s contact data, a subsequent administrator status change with customer notifications enabled delivers the victim-s appointment notification to the attacker-controlled email address.

CVSS 5.4EPSS 0.146%Κίνδυνος 0.55
Προβολή πηγής
Δημοσίευση
2026-07-29 07:16:41
Επηρεαζόμενες εκδόσεις
<=3.12.26
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-08-10 13:17:57
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N