What is CVE-2026-14223?
This vulnerability affects the Easy Appointments WordPress plugin up to version 3.12.26. It fails to verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. It is recommended to update the plugin to the latest version immediately.
Azərbaycanca: Bu boşluq 'Easy Appointments' WordPress plagininin 3.12.26 versiyasına qədər olanlara təsir edir. O, müştəri məlumatlarını göstərərkən sahibliyi və ya səlahiyyətləri yoxlamır, bu səbəbdən sadəcə abunəçi (subscriber) səviyyəli girişi olan istifadəçilər identifikatoru dəyişərək istənilən müştərinin şəxsi məlumatlarını oxuya bilər. Ən qısa zamanda plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the 'Easy Appointments' plugin are affected by CVE-2026-14223?
This vulnerability affects all versions of the plugin up to and including 3.12.26.
What level of access does an attacker need to exploit CVE-2026-14223?
The attacker only needs subscriber-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.