What is CVE-2026-14224?
An authorization bypass vulnerability in the Easy Appointments WordPress plugin (through 3.12.26) allows any authenticated user, including subscribers, to modify other users' appointment data by exploiting a shared nonce. Update the plugin to the latest version immediately.
Azərbaycanca: Easy Appointments WordPress plaginində (3.12.26-ə qədər) identifikasiya zəifliyi aşkar edilib. İstənilən autentifikasiya olunmuş istifadəçi (məs. subscriber) paylaşılan nonce vasitəsilə digər müştərilərin görüş məlumatlarını dəyişə bilər. Dərhal plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which users can exploit the Easy Appointments plugin vulnerability?
Due to the authorization bypass vulnerability, any authenticated user, including subscribers, can modify other customers' appointment data.
What should be done to fix the CVE-2026-14224 vulnerability?
Update the Easy Appointments plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.