What is CVE-2026-14221?
The Easy Appointments WordPress plugin up to version 3.12.26 lacks proper capability checks, relying solely on a nonce obtainable by any authenticated user. This allows contributor-level users to read all customers' appointment details. Administrators should immediately update or deactivate the plugin.
Azərbaycanca: Easy Appointments WordPress plaqinində (3.12.26 daxil olmaqla) səlahiyyət yoxlaması çatışmazlığı aşkarlanıb. Bu zəiflik contributor səviyyəli autentifikasiya olunmuş istifadəçilərə yalnız hər kəsin əldə edə biləcəyi nonce ilə bütün müştərilərin görüş detallarını oxumağa imkan verir. Sayt inzibatçıları plaqini dərhal son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Easy Appointments WordPress plugin are vulnerable to CVE-2026-14221?
Versions up to and including 3.12.26 are affected by this vulnerability.
What privilege level does an attacker need to exploit CVE-2026-14221?
An attacker must be an authenticated user with contributor-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.