Descripción
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment-s edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user-s appointment. Because the Easy Appointments WordPress plugin before 3.12.28 then treats that metadata as the appointment-s contact data, a subsequent administrator status change with customer notifications enabled delivers the victim-s appointment notification to the attacker-controlled email address.
- Publicación
- 2026-07-29 07:16:41
- Versiones afectadas
- <=3.12.26
- Tipo
- Aplicación web
- Última modificación
- 2026-08-10 13:17:57
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N