What is CVE-2026-14222?
CVE-2026-14222: The Easy Appointments WordPress plugin through version 3.12.26 fails to perform proper capability and nonce checks in its connection-deletion action. This allows authenticated attackers with contributor-level access to delete the booking configuration and disable the booking system. Users should update to the latest patched version.
Azərbaycanca: CVE-2026-14222: Easy Appointments WordPress plagini 3.12.26-ə qədər versiyalarda 'connection-deletion' əməliyyatı üzrə müvafiq səlahiyyət (capability) və nonce yoxlaması aparmır. Bu boşluq 'Contributor' səviyyəsində girişi olan istifadəçilərə bron konfiqurasiyasını silməyə və rezervasiya sistemini sıradan çıxarmağa imkan verir. Plaginin son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin and versions are affected by CVE-2026-14222?
The vulnerability affects the Easy Appointments WordPress plugin through version 3.12.26.
What can an authenticated attacker do by exploiting CVE-2026-14222?
An authenticated attacker with contributor-level access can delete the booking configuration and disable the booking system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.