What is CVE-2026-14188?
The Easy Appointments WordPress plugin through version 3.12.26 lacks per-request capability or nonce checks on a customer-listing handler, allowing authenticated users with contributor-level access to read all stored customers' personal information.
Azərbaycanca: Easy Appointments WordPress plaginində (3.12.26 versiyasına qədər) müştəri siyahısı göstərən funksiyada hər sorğu üçün capability və ya nonce yoxlanışı aparılmır. Bu boşluq, contributor səviyyəli autentifikasiya olunmuş istifadəçilərə bütün müştərilərin şəxsi məlumatlarını oxumağa imkan verir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Is authentication required to exploit the CVE-2026-14188 vulnerability?
Yes, the vulnerability requires an authenticated user, but only contributor-level access is sufficient.
What type of data can be exposed through this vulnerability?
It allows reading all stored customers' personal information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.